HIGH 8.8 Go

mrpack-install vulnerable to path traversal with dependency

GHSA-r887-gfxh-m9rr · CVE-2023-25307 · GO-2023-1543

Published · Modified

Description

Impact

Importing a malicious .mrpack file can cause path traversal while downloading files.
This can lead to scripts or config files being placed or replaced at arbitrary locations, without the user noticing.

Patches

No patches yet.

Workarounds

Avoid importing .mrpack files from untrusted sources.

References

https://docs.modrinth.com/docs/modpacks/format_definition/#files

Ready to move

Start Securing

Free, no credit card | First findings in minutes