CVE-2026-42448: Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
A receiver who specifies “–output ” where that output directory currently exists (as a directory).
References
Code Behaviors & Features
Detect and mitigate CVE-2026-42448 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →