{"id":"UBUNTU-CVE-2024-54132","details":"The GitHub CLI is GitHub’s official command line tool. A security vulnerability has been identified in GitHub CLI that could create or overwrite files in unintended directories when users download a malicious GitHub Actions workflow artifact through gh run download. This vulnerability stems from a GitHub Actions workflow artifact named .. when downloaded using gh run download. The artifact name and --dir flag are used to determine the artifact’s download path. When the artifact is named .., the resulting files within the artifact are extracted exactly 1 directory higher than the specified --dir flag value. This vulnerability is fixed in 2.63.1.","modified":"2026-02-05T20:58:43.571026Z","published":"2024-12-04T16:15:00Z","related":["USN-8012-1"],"upstream":["CVE-2024-54132"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-54132"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2024-54132"},{"type":"REPORT","url":"https://github.com/cli/cli/security/advisories/GHSA-2m9h-r57g-45pj"},{"type":"REPORT","url":"https://github.com/cli/cli/commit/1136764c369aaf0cae4ec2ee09dc35d871076932"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8012-1"}],"affected":[{"package":{"name":"gh","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/gh@2.45.0-1ubuntu0.3+esm2?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.45.0-1ubuntu0.3+esm2"}]}],"versions":["2.27.0+dfsg1-1build1","2.30.0-2","2.35.0-1","2.40.1+dfsg1-1","2.42.1-1","2.43.1-1","2.44.1-1","2.44.1-2","2.45.0-1","2.45.0-1build1","2.45.0-1ubuntu0.1","2.45.0-1ubuntu0.2","2.45.0-1ubuntu0.2+esm1","2.45.0-1ubuntu0.2+esm2","2.45.0-1ubuntu0.3","2.45.0-1ubuntu0.3+esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"gh","binary_version":"2.45.0-1ubuntu0.3+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2024/UBUNTU-CVE-2024-54132.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/U:Green"},{"type":"Ubuntu","score":"medium"}]}