GHSA-8qch-vj6m-2694
GitHub Security Advisory
luigi Arbitrary File Write via Archive Extraction (Zip Slip)
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.
Affected Packages
PyPI
luigi
Affected versions:
0
(fixed in 3.6.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 14, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.