The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Relative Path Traversal vulnerabilities in an interactive lesson.
Start learningUpgrade githacker to version 1.1.10 or higher.
githacker is an A multiple threads tool to download the .git folder and rebuild git repository locally.
Affected versions of this package are vulnerable to Relative Path Traversal via the add_head_file_tasks function. An attacker can access arbitrary local files and exfiltrate fragments of their contents by tricking a user into running the application against a malicious server that returns crafted .git/HEAD responses. This is only exploitable if the victim runs the tool against a URL controlled by the attacker.
This vulnerability can be mitigated by running the application inside a disposable container and avoiding use with untrusted URLs.