Vulnerability Description
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-9118?
CVE-2025-9118 is a documented vulnerability. A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously craf...
How severe is CVE-2025-9118?
CVSS scoring is not yet available for CVE-2025-9118. Check NVD for updates.
Is there a patch for CVE-2025-9118?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.