CVE-2023-25307High· 8.8▾ Twilightmrpack-install vulnerable to path traversal with dependency
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
Importing a malicious .mrpack file can cause path traversal while downloading files.
This can lead to scripts or config files being placed or replaced at arbitrary locations, without the user noticing.
No patches yet.
Avoid importing .mrpack files from untrusted sources.
https://docs.modrinth.com/docs/modpacks/format_definition/#files
github.com/nothub/mrpack-install < 0.16.3Upgrade to a patched release:
github.com/nothub/mrpack-install 0.16.3