Unknown · Safearchive · CVE-2024-10389
**Name of the Vulnerable Software and Affected Versions**
Safearchive versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc
**Description**
The issue is related to a Path Traversal vulnerability in Safearchive on platforms with case-insensitive filesystems, such as NTFS. This vulnerability allows attackers to write arbitrary files via archive extraction containing symbolic links.
**Recommendations**
For versions prior to commit f7ce9d7b6f9c6ecd72d0b0f16216b046e55e44dc, upgrade past this commit to resolve the issue. As a temporary workaround, consider restricting the use of archive extraction containing symbolic links until a patch is available.