PT-2025-34599 · Google · Google Cloud Dataform

Tomas Lažauninkas

·

Published

2025-08-25

·

Updated

2025-08-25

·

CVE-2025-9118

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H

Name of the Vulnerable Software and Affected Versions:

Google Cloud Dataform (affected versions not specified)

Description:

A path traversal vulnerability exists in the NPM package installation process of Google Cloud Dataform. A remote attacker can read and write files in other customers' repositories by using a maliciously crafted package.json file. No customer action is required as Google has already applied mitigations.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-9118

Affected Products

Google Cloud Dataform