216.73.217.22

CVE-2025-9118

· Published 25/08/2025 07:15 · Modified 25/08/2025 07:15

Labels: CVE-2025-9118 2025-08-25CVE-2025-9118CWE-22f45cbf4e-4146-4068-b7e1-655ffc2c548c

Essential information

Published
25/08/2025 07:15
Modified
25/08/2025 07:15
Author
Creator
CVSS
10.0 CRITICAL (v3) 10.0 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
f45cbf4e-4146-4068-b7e1-655ffc2c548c
NVD
View on NVD

Affected products (CPE)

ProductCPE
google / cloud dataform cpe:2.3:a:google:cloud_dataform:*:*:*:*:*:*:*:*

References