Ali Razmjoo

1 exploit Active since Dec 2024
CVE-2024-21542 WRITEUP HIGH WRITEUP
luigi < 3.6.0 - Arbitrary File Write via Archive Extraction
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.
CVSS 8.6