A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
History

Mon, 25 Aug 2025 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google cloud Platform
Vendors & Products Google
Google cloud Platform

Mon, 25 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 25 Aug 2025 07:15:00 +0000

Type Values Removed Values Added
Description A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
Title Dataform Path Traversal
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GoogleCloud

Published:

Updated: 2025-08-25T13:48:40.821Z

Reserved: 2025-08-18T15:08:00.732Z

Link: CVE-2025-9118

cve-icon Vulnrichment

Updated: 2025-08-25T13:48:37.930Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-25T07:15:35.803

Modified: 2025-08-25T20:24:45.327

Link: CVE-2025-9118

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-25T22:08:14Z