internetarchive@5.4.1 vulnerabilities

A Python interface to archive.org.

  • latest version

    5.5.1

  • latest non vulnerable version

  • first published

    12 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the internetarchive package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Directory Traversal

    internetarchive is an A Python interface to archive.org.

    Affected versions of this package are vulnerable to Directory Traversal via the download function in the file.py file, which does not properly sanitize user-supplied filenames or validate the final download path. An attacker can write files outside the intended directory by supplying crafted filenames containing path traversal sequences.

    How to fix Directory Traversal?

    Upgrade internetarchive to version 5.5.1 or higher.

    [,5.5.1)