GHSA-rq6q-wr2q-7pgp
HIGHCVE-2026-24046Multiple Scaffolder actions and archive extraction utilities were vulnerable to symlink-based path traversal attacks. An attacker with access to create and execute Scaffolder templates could exploit symlinks to:
- Affected
- < 0.12.2
- Fixed in
- 0.12.2
- Weakness
- CWE-22
- Published
- 2026-01-21
- Source
- github