Google Cloud Dataform Path Traversal Vulnerability in NPM Package Installation
Vulnerability
A path traversal vulnerability has been identified in the NPM package installation process of Google Cloud Dataform. This vulnerability allows remote attackers to read and write files in other customers' repositories by using a maliciously crafted package.json file.
Impact
Exploitation of this vulnerability could lead to unauthorized access to read and write files in affected customers' repositories.
Added: Aug 25, 2025, 7:17 AM
Updated: Aug 25, 2025, 7:17 AM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
1.3exploitability
6.4remediation
0.0relevance
0.4threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
