CVE-2025-9118 | Google Cloud Dataform prior 08/21/2025 NPM Package Installation package.json path traversal (gcp-2025-045)

SecurityVulns

A vulnerability, which was classified as critical, has been found in Google Cloud Dataform. Affected by this issue is some unknown functionality of the file package.json of the component NPM Package Installation Handler. The manipulation leads to path traversal.

This vulnerability is referenced as CVE-2025-9118. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More