HIGH 8.8 Go
mrpack-install vulnerable to path traversal with dependency
GHSA-r887-gfxh-m9rr · CVE-2023-25307 · GO-2023-1543
Published · Modified
Description
Impact
Importing a malicious .mrpack file can cause path traversal while downloading files.
This can lead to scripts or config files being placed or replaced at arbitrary locations, without the user noticing.
Patches
No patches yet.
Workarounds
Avoid importing .mrpack files from untrusted sources.
References
https://docs.modrinth.com/docs/modpacks/format_definition/#files
References
- WEB https://github.com/nothub/mrpack-install/security/advisories/GHSA-r887-gfxh-m9rr
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2023-25307
- WEB https://github.com/nothub/mrpack-install/commit/a1f424b6a616d2de95228781eef3b92b9769f23c
- PACKAGE https://github.com/nothub/mrpack-install
- WEB https://github.com/nothub/mrpack-install/releases/tag/v0.16.3
- WEB https://quiltmc.org/en/blog/2023-02-04-five-installer-vulnerabilities
Ready to move
Start Securing
Free, no credit card | First findings in minutes