Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. react-native-document-picker
  4. ›
  5. CVE-2024-25466

CVE-2024-25466: React Native Document Picker Directory Traversal vulnerability

February 16, 2024 (updated March 27, 2025)

Directory Traversal vulnerability in React Native Document Picker before 8.2.2 and 9.x before 9.1.1 allows a local attacker to execute arbitrary code via a crafted script to the Android library component.

References

  • github.com/FixedOctocat/CVE-2024-25466/tree/main
  • github.com/advisories/GHSA-pmgm-h3cc-m4hj
  • github.com/rnmods/react-native-document-picker
  • github.com/rnmods/react-native-document-picker/blob/0be5a70c3b456e35c2454aaf4dc8c2d40eb2ab47/android/src/main/java/com/reactnativedocumentpicker/RNDocumentPickerModule.java
  • github.com/rnmods/react-native-document-picker/commit/1ae7cb217d23a551bff86ad10c7ae6f5e074490f
  • github.com/rnmods/react-native-document-picker/commit/ad0b5e58252eba56a5a3b22311a66ffa5e65cffe
  • github.com/rnmods/react-native-document-picker/pull/698
  • github.com/rnmods/react-native-document-picker/releases/tag/v8.2.2
  • nvd.nist.gov/vuln/detail/CVE-2024-25466

Code Behaviors & Features

Detect and mitigate CVE-2024-25466 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 8.2.2, all versions starting from 9.0.0 before 9.1.1

Fixed versions

  • 9.1.1
  • 8.2.2

Solution

Upgrade to versions 8.2.2, 9.1.1 or above.

Impact 7.8 HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-26: Path Traversal: '/dir/../filename'

Source file

npm/react-native-document-picker/CVE-2024-25466.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:05 +0000.