Junglewise Threat Intelligence

CVE-2024-54132: GO-2024-3310 - Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability in github.com/cli/cli

CVE-2024-54132 · Severity: medium · CVSS 4 · Published 2024-12-04

Technologies: github.com/cli/cli (Go), github.com/cli/cli/v2 (Go). Vendors: Go.

Executive brief

Downloading malicious GitHub Actions workflow artifact results in path traversal vulnerability in github.com/cli/cli

Affected products

  • Go github.com/cli/cli
  • Go github.com/cli/cli/v2

Related threats