High severity7.3NVD Advisory· Published Sep 2, 2024· Updated Jun 17, 2026
CVE-2024-42471
CVE-2024-42471
Description
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of actions/artifact on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using downloadArtifactInternal, downloadArtifactPublic, or streamExtractExternal for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@actions/artifactnpm | >= 2.0.0, < 2.1.2 | 2.1.2 |
Affected products
2Patches
Vulnerability mechanics
References
9- github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3nvdVendor AdvisoryWEB
- github.com/advisories/GHSA-6q32-hq47-5qq3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-42471ghsaADVISORY
- github.com/actions/download-artifact/blob/v3/package.jsonghsaWEB
- github.com/actions/toolkit/commit/29885a805ef3e95a9862dcaa8431c30981960017ghsaWEB
- github.com/actions/toolkit/pull/1602ghsaWEB
- github.com/actions/toolkit/pull/1666nvdWEB
- github.com/actions/toolkit/pull/1724ghsaWEB
- snyk.io/research/zip-slip-vulnerabilitynvdNot ApplicableWEB
News mentions
0No linked articles in our index yet.