Importing a malicious .mrpack file can cause path traversal while downloading files.
This can lead to scripts or config files being placed or replaced at arbitrary locations, without the user noticing.
No patches yet.
Avoid importing .mrpack files from untrusted sources.
https://docs.modrinth.com/docs/modpacks/format_definition/#files
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed_at": "2023-02-08T18:07:16Z",
"nvd_published_at": "2023-06-26T15:15:09Z",
"severity": "HIGH",
"github_reviewed": true
}