texbld@0.1.2 vulnerabilities

A dockerized build tool for paper compilation

Direct Vulnerabilities

Known vulnerabilities in the texbld package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • C
Directory Traversal

texbld is a dockerized build tool for paper compilation

Affected versions of this package are vulnerable to Directory Traversal in the validate_image_files() function in scaffold/copy.py. An attacker can cause arbitrary modifications on the affected file system by uploading an image to Github using a relative path to point to the image.

How to fix Directory Traversal?

Upgrade texbld to version 0.2.0 or higher.

[,0.2.0)