Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Low severity
GitHub Reviewed
Published
May 5, 2026
in
magic-wormhole/magic-wormhole
•
Updated Jun 8, 2026
Description
Published to the GitHub Advisory Database
May 6, 2026
Reviewed
May 6, 2026
Published by the National Vulnerability Database
May 26, 2026
Last updated
Jun 8, 2026
Impact
A receiver who specifies "--output
" where that output directory currently exists (as a directory).Patches
0.24.0 will contain the patch
Workarounds
Ensure local target directories specified by "--output" do not already exist
Resources
Private email and Signal communications from a user.
Magic Wormhole thanks @marduc812
References