Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
Low severity
GitHub Reviewed
Published
May 5, 2026
in
magic-wormhole/magic-wormhole
•
Updated May 6, 2026
Description
Published to the GitHub Advisory Database
May 6, 2026
Reviewed
May 6, 2026
Last updated
May 6, 2026
Impact
A receiver who specifies "--output
" where that output directory currently exists (as a directory).Patches
0.24.0 will contain the patch
Workarounds
Ensure local target directories specified by "--output" do not already exist
Resources
Private email and Signal communications from a user.
Magic Wormhole thanks @marduc812
References