THREAT OPS › Threat News › [GHSA] GHSA-2mf3-mr2r-r4vf (high) — @rhinostone/swig: arbitrary local file read via include/extends path traversal
[GHSA] GHSA-2mf3-mr2r-r4vf (high) — @rhinostone/swig: arbitrary local file read via include/extends path traversal
GHSA-2mf3-mr2r-r4vf Severity: high CVE: None
@rhinostone/swig: arbitrary local file read via include/extends path traversal
### Overview
`@rhinostone/swig` is a maintained fork of the abandoned `swig` template engine and inherited the directory-traversal vulnerability tracked upstream as CVE-2023-25345 / GHSA-2rq5-699j-x7p6. The `{% include %}`, `{% extends %}`, and `{% import %}` tags resolve
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- 381bdc305e0b10e45368d56324328b9b4f7017fcsha1
- CVE-2023-25345cve
Original source: https://github.com/advisories/GHSA-2mf3-mr2r-r4vf