NONE · 0

CVE-2025-9118

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously craf...

Vulnerability Description

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-9118?

CVE-2025-9118 is a documented vulnerability. A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously craf...

How severe is CVE-2025-9118?

CVSS scoring is not yet available for CVE-2025-9118. Check NVD for updates.

Is there a patch for CVE-2025-9118?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.