CVE-2025-9118

Publication date

2025-08-25 07:05:31

Family

GoogleCloud

State

PUBLISHED

Description

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers repositories via a maliciously crafted package.json file.