---
id: GHSA-2h46-9x5w-4wf7
title: >-
  Entire CLI: Path traversal in checkpoint session metadata allows arbitrary
  file write during resume/rewind
summary: >-
  Entire CLI: Path traversal in checkpoint session metadata allows arbitrary
  file write during resume/rewind
severity: medium
cwe:
  - CWE-22
  - CWE-73
vendor: entireio
product: github.com/entireio/cli
affected:
  - github.com/entireio/cli <= 0.7.6
patched:
  - github.com/entireio/cli 0.7.7
published: '2026-06-19'
updated: '2026-06-19'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-2h46-9x5w-4wf7'
references:
  - url: 'https://github.com/entireio/cli/security/advisories/GHSA-2h46-9x5w-4wf7'
  - url: 'https://github.com/entireio/cli/pull/1365'
  - url: 'https://github.com/entireio/cli/pull/1449'
  - url: 'https://github.com/advisories/GHSA-2h46-9x5w-4wf7'
tags:
  - ghsa
  - go
ingestedAt: '2026-06-22T15:59:08.178Z'
ecosystem: go
---

## Overview

### Impact

A path traversal vulnerability in Entire CLI allows an attacker with push access to the checkpoints repository to craft malicious checkpoint metadata that causes `entire session resume` or `entire checkpoint rewind` to write attacker-controlled transcript data outside of the expected session directory.

The issue occurs because checkpoint metadata is fetched from the remote `entire/checkpoints/v1` branch and the `SessionID` field was used to construct filesystem paths without validation in the restore path. A malicious `SessionID` containing absolute paths or path traversal sequences could cause arbitrary files on the victim’s machine to be overwritten.

### Patches

The patched versions (`v0.7.7` or `v0.7.8-nightly.*`) observe stronger input validation and enforce traversal-resistant primitives to ensure that only descending directories can be accessed by the affected commands. 

### Workarounds
If upgrading immediately is not possible:

- Do not run `entire session resume` or `entire checkpoint rewind` on repositories where untrusted users can push to `entire/checkpoints/v1`.
- Restrict push access to shared repositories until all collaborators have upgraded.
- Inspect the `entire/checkpoints/v1` branch for suspicious checkpoint metadata before resuming or rewinding.
- Remove or protect shell initialization files and other sensitive user-writable files where feasible.

These mitigations reduce exposure but do not fully address the vulnerability. Upgrading is recommended.

### Credits
Thanks Navtej Kathuria for privately reporting this issue to the Entire Security team.

## Affected packages

- `github.com/entireio/cli <= 0.7.6`

## Remediation

Upgrade to a patched release:

- `github.com/entireio/cli 0.7.7`
