Advisories for Pypi/Hyper-Bump-It package

2023

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

hyper-bump-it is a command line tool for updating the version in project files.hyper-bump-it reads a file glob pattern from the configuration file. That is combined with the project root directory to construct a full glob pattern that is used to find files that should be edited. These matched files should be contained within the project root directory, but that is not checked. This could result in changes being written to …