PT-2024-23301 · Mesonlsp · Mesonlsp

Jcwasmx86

·

Published

2024-04-04

·

Updated

2024-04-04

·

CVE-2024-30254

CVSS v3.1

5.8

Medium

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions MesonLSP versions prior to 4.1.4
Description A vulnerability in MesonLSP allows overwriting arbitrary files if an attacker can make the victim run the language server within a specific crafted project or execute mesonlsp --full.
Recommendations For versions prior to 4.1.4, update to version 4.1.4 to resolve the issue. As a temporary workaround, avoid running mesonlsp --full and set the language server option others.neverDownloadAutomatically to true.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2024-30254
GHSA-48C5-35FH-846H

Affected Products

Mesonlsp