CVE-2024-54132 - CVE House
Back to Database
Status published Medium CVE-2024-54132

GitHub CLI allows downloading malicious GitHub Actions workflow artifact to result in path traversal vulnerability

Vulnerability Description

The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions workflow artifact named .. when downloaded using gh run download. The artifact name and --dir flag are used to determine the artifact’s download path. When the artifact is named .., the resulting files within the artifact are extracted exactly 1 directory higher than the specified --dir flag value. This vulnerability is fixed in 2.63.1.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-54132

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

cli
Vulnerable Versions:
< 2.63.1

Timeline

Official Publish: December 4th, 2024
Last Modified: December 4th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)