CVE-2024-42471 affects the GitHub ToolKit component actions/artifact. Versions on the 2.x branch prior to 2.1.2 are vulnerable to arbitrary file write during artifact extraction. The issue occurs in the artifact download and extraction paths downloadArtifactInternal, downloadArtifactPublic, and streamExtractExternal when processing a specially crafted artifact containing path traversal filenames. Because extraction does not adequately constrain file paths to the intended destination directory, attacker-controlled archive entries can traverse out of the target extraction path and write files to unintended locations on the filesystem.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
actions/artifact to version 2.1.2 or later. The vulnerable 2.x versions prior to 2.1.2 should no longer be used for artifact download and extraction. Validate that all workflows, dependencies, and pinned action references are updated to a fixed release.1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit for CVE-2024-42471, a file write/overwrite vulnerability in the unzip-stream library (version 0.3.1). The exploit consists of a single Python script (exploit.py) that creates a malicious ZIP archive. The archive contains a file with a directory traversal path in its name, allowing it to overwrite arbitrary files when extracted by a vulnerable unzip-stream implementation. The script requires a source file ('./poc') to include in the ZIP and specifies a target file path ('home/mcsam/pocc') to overwrite on the victim's system. The exploit also notes that Python's zipfile module must be modified to bypass arcname normalization for the PoC to work as intended. The attack vector is local, as it requires the victim to extract the crafted ZIP file using the vulnerable library. No network endpoints are present; all identified endpoints are file paths relevant to the exploit's operation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.