Versions of actions/download-artifact
before 4.1.7 are vulnerable to arbitrary file write when downloading and extracting a specifically crafted artifact that contains path traversal filenames.
Upgrade to version 4.1.7 or higher. Alternatively use 'v4' tag which points to the latest and secure version.
CVE-2024-42471
Justin Taft from Google
{ "nvd_published_at": null, "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-09-03T20:55:34Z" }