Launch Week Day 1: Announcing Security Design Review
LOW 3.5 PyPI

Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed

GHSA-cf92-gfcw-6v53 · CVE-2026-42448

Published · Modified

Description

Impact

A receiver who specifies "--output

" where that output directory currently exists (as a directory).

Patches

0.24.0 will contain the patch

Workarounds

Ensure local target directories specified by "--output" do not already exist

Resources

Private email and Signal communications from a user.
Magic Wormhole thanks @marduc812

Ready to move

Start Securing

Free, no credit card | First findings in minutes