—
PYSEC-2024-159
Quick fix
PYSEC-2024-159 — luigi: upgrade to the fixed version with the command below.
pip install --upgrade 'luigi>=b5d1b965ead7d9f777a3216369b5baf23ec08999'Details
Versions of the package luigi before 3.6.0 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) due to improper destination file path validation in the _extract_packages_archive function.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/luigi
Introduced in:
0Fixed in: b5d1b965ead7d9f777a3216369b5baf23ec08999Fix
pip install --upgrade 'luigi>=b5d1b965ead7d9f777a3216369b5baf23ec08999'References
- https://github.com/spotify/luigi/commit/b5d1b965ead7d9f777a3216369b5baf23ec08999[FIX]
- https://github.com/spotify/luigi/issues/3301[REPORT]
- https://github.com/spotify/luigi/releases/tag/v3.6.0[WEB]
- https://security.snyk.io/vuln/SNYK-PYTHON-LUIGI-7830489[WEB]
- https://github.com/advisories/GHSA-8qch-vj6m-2694[ADVISORY]