GHSA-p498-v437-472g: humanfs: Recursive copy follows symlinked files and copies data from outside the source tree
@humanfs/node does not treat symlinks as a separate case during copy operations. A symlink placed inside an attacker-controlled source tree can make copyAll() read and copy the contents of any file readable by the process, even when that file is outside the directory being copied.
References
Code Behaviors & Features
Detect and mitigate GHSA-p498-v437-472g with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →