mat2@0.12.1 vulnerabilities

mat2 is a metadata removal tool, supporting a wide range of commonly used file formats, written in python3: at its core, it's a library, used by an eponymous command-line interface, as well as several file manager extensions.

  • latest version

    0.13.5

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    2 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the mat2 package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • C
    Arbitrary File Write via Archive Extraction (Zip Slip)

    mat2 is an A metadata removal tool supporting a wide range of commonly used file formats

    Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) during the ZIP archive cleaning process, which allows arbitrary reads on the affected file system, including sensitive files like app.secret_key. This could allow arbitrary code execution.

    How to fix Arbitrary File Write via Archive Extraction (Zip Slip)?

    Upgrade mat2 to version 0.13.0 or higher.

    [,0.13.0)