Impact
A path traversal flaw exists in the receiver side of Magic Wormhole when the user specifies the --output option pointing at an already existing directory. The flaw allows the receiver to write files outside the intended output location, potentially overwriting existing files within that directory. The vulnerability is classified as CWE‑22 and can lead to local modification of files, compromising data integrity.
Affected Systems
The flaw affects all versions of Magic Wormhole prior to 0.24.0. Users running any older release should verify their installed version and plan an upgrade if possible.
Risk and Exploitability
The CVSS score of 3.5 indicates low to moderate severity. No EPSS data is available and the issue is not listed in the CISA KEV catalog, suggesting limited exploitation. The attack requires local execution of the receiver command and a pre‑existing output directory; it does not provide remote code execution. The risk is primarily to file integrity on the local machine, with a modest likelihood of exploitation under the stated conditions.
OpenCVE Enrichment
Github GHSA