skilo cargo Package Vulnerability: Arbitrary Local File Disclosure
An early warning has been issued regarding a vulnerability in the skilo cargo package where the 'add' command mishandles symbolic links, potentially allowing a malicious skill source to disclose arbitrary local files.
What happened
The skilo cargo package's 'add' command is reportedly mishandling symbolic links, which could allow a malicious skill source to read arbitrary local files and place their contents inside the installed skill directory. This vulnerability, tracked under GHSA-6XX4-9WP6-65P7, affects skilo versions prior to 0.11.1. It is under investigation and has been classified as a critical CVE. Professional software engineers using skilo should upgrade to version 0.11.1 or later to mitigate this risk. Additionally, it is recommended to avoid installing skills from untrusted sources and to inspect skill sources for symbolic links before using the'skilo add' command.
How 0Day mitigates this
skilo is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.