Vulnerability CVE-2024-42471


Published: 2024-09-02

Description:
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` before 2.1.7 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.7 or higher. There are no known workarounds for this issue.

See advisories in our WLB2 database:
Topic
Author
Date
High
unzip-stream 0.3.1 Arbitrary File Write
Ardayfio Samuel ...
01.05.2025

 References:
https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3
https://github.com/actions/toolkit/pull/1724
https://snyk.io/research/zip-slip-vulnerability

Copyright 2026, cxsecurity.com

 

Back to Top