Executive brief
@actions/artifact is a GitHub Actions library used to download and extract build artifacts in CI/CD workflows. A path traversal vulnerability in versions 2.0.0–2.1.1 allows attackers to write files outside the intended extraction directory when processing a specially crafted artifact, potentially compromising the build environment or injecting malicious code into workflows.
Technical details
The vulnerability is a classic zip-slip path traversal (CWE-22) in the artifact extraction functions downloadArtifactInternal, downloadArtifactPublic, and streamExtractExternal. An attacker can craft an artifact with filenames containing path traversal sequences (e.g., ../../../) that bypass directory restrictions during extraction, allowing arbitrary file writes. The vulnerability requires an attacker to provide the malicious artifact to a CI workflow, but no authentication or user interaction beyond workflow execution is needed. An exploited workflow could allow code injection, configuration tampering, or environment variable manipulation. The fix is available in version 2.1.2 or later.
Affected products
- GitHub @actions/artifact 2.0.0 to 2.1.1
Timeline
- 2024-09-02: disclosed: Public disclosure via GitHub advisory
- 2024-09-02: patched: Version 2.1.2 released with fix
- 2024-09-03: advisory: CVE-2024-42471 published