Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @boxlite-ai/boxlite to version 0.9.0 or higher.
@boxlite-ai/boxlite is a BoxLite - Embeddable micro-VM runtime for secure, isolated code execution
Affected versions of this package are vulnerable to Symlink Attack via improper path resolution during extraction of OCI image layer tarballs. An attacker can write arbitrary files to locations outside the intended extraction root by crafting a layer with a symlink pointing to an absolute host path and including file entries that traverse this symlink.