CVE-2025-9118: Dataform Path Traversal
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9118?
CVE-2025-9118 is considered a high severity vulnerability due to its potential for remote file access.
How do I fix CVE-2025-9118?
To mitigate CVE-2025-9118, ensure all package.json files in your repositories are from trusted sources and validate their contents.
What is the impact of CVE-2025-9118?
CVE-2025-9118 allows attackers to exploit path traversal to read and write files in affected customers' repositories.
Who is affected by CVE-2025-9118?
All users of Google Cloud Dataform that leverage NPM package installations may be affected by CVE-2025-9118.
When was CVE-2025-9118 disclosed?
CVE-2025-9118 was disclosed in 2025 and has since been a significant concern for users of Google Cloud Dataform.