VDB
Sign up
—

PYSEC-2024-159

Quick fix

PYSEC-2024-159 — luigi: upgrade to the fixed version with the command below.

pip install --upgrade 'luigi>=b5d1b965ead7d9f777a3216369b5baf23ec08999'

Details

Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/luigi
Introduced in: 0Fixed in: b5d1b965ead7d9f777a3216369b5baf23ec08999
Fixpip install --upgrade 'luigi>=b5d1b965ead7d9f777a3216369b5baf23ec08999'

References