Executive brief
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability in github.com/cli/cli
Affected products
- Go github.com/cli/cli
- Go github.com/cli/cli/v2
Junglewise Threat Intelligence
CVE-2024-54132 · Severity: medium · CVSS 4 · Published 2024-12-04
Technologies: github.com/cli/cli (Go), github.com/cli/cli/v2 (Go). Vendors: Go.
Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability in github.com/cli/cli