← Back to browse · API

CVE-2025-9118

Severity
CRITICAL
CVSS
10.0
EPSS
0.00648
Risk score
40.23
CISA KEV
No
PoC
No
Published
2025-08-25
Modified
2025-08-25
First seen
2026-08-07
Aliases
EUVD-2025-25690, GHSA-3CPQ-GX29-GW6M
Products
Google Cloud:Dataform 08/7/2025 <08/21/2025
Sources
euvd EUVD-2025-25690

Description

A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.

References