A path traversal vulnerability in the NPM package...
Critical severity
Unreviewed
Published
Aug 25, 2025
to the GitHub Advisory Database
•
Updated Aug 25, 2025
Description
Published by the National Vulnerability Database
Aug 25, 2025
Published to the GitHub Advisory Database
Aug 25, 2025
Last updated
Aug 25, 2025
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
References