← العودة للجدول
GHSA-wx3m-whqv-xv47 — GHSA: skillctl: Path traversal and symlink-follow in skillctl allow arbitrary file disclosure and deletion
📅 2026-06-05
🟠 High 🔥 No GHSA Wiper Microsoft

📋 الوصف الكامل

## Impact `skillctl` 0.1.0 and 0.1.1 contained four path-safety vulnerabilities that, in combination, allowed an attacker to: 1. **Exfiltrate arbitrary files on the operator's machine** by publishing a malicious skills library containing a symlink inside a skill folder (e.g. `niania → /home/user/.aws/credentials`). The symlink fell through `entry.file_type().is_dir()` in `fs_util::copy_di

💻 الأنظمة المتأثرة

GHSA-wx3m-whqv-xv47 — GHSA:

⚠️ نوع التهديد

Wiper

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ←