Vulnerability record · CVE-2022-23530 · published 16 December 2022
CVE-2022-23530: Datadoghq guarddog path traversal vulnerability
Datadoghq · Guarddog
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package. Extracting files using shutil.unpack_archive() from a potentially malicious tarball without validating that the destination file path is within the intended destination directory can cause files outside the destination directory to be overwritten. This issue is patched in version 0.1.8. Potential workarounds include using a safer module, like zipfile, and validating the location of the extracted files and discarding those with malicious paths.
Description
GuardDog is a CLI tool to identify malicious PyPI packages. Versions prior to v0.1.8 are vulnerable to arbitrary file write when scanning a specially-crafted remote PyPI package. Extracting files using shutil.unpack_archive() from a potentially malicious tarball without validating that the destination file path is within the intended destination directory can cause files outside the destination directory to be overwritten. This issue is patched in version 0.1.8. Potential workarounds include using a safer module, like zipfile, and validating the location of the extracted files and discarding those with malicious paths.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/DataDog/guarddog/blob/a1d064ceb09d39bb28deb6972bc0a278756ea91f/guarddog/scanners/package_scanner.py#L | ExploitThird Party Advisory |
| https://github.com/DataDog/guarddog/commit/37c7d0767ba28f4df46117d478f97652594c491c | PatchThird Party Advisory |
| https://github.com/DataDog/guarddog/security/advisories/GHSA-78m5-jpmf-ch7v | ExploitThird Party Advisory |
| https://github.com/DataDog/guarddog/blob/a1d064ceb09d39bb28deb6972bc0a278756ea91f/guarddog/scanners/package_scanner.py#L | ExploitThird Party Advisory |
| https://github.com/DataDog/guarddog/commit/37c7d0767ba28f4df46117d478f97652594c491c | PatchThird Party Advisory |
| https://github.com/DataDog/guarddog/security/advisories/GHSA-78m5-jpmf-ch7v | ExploitThird Party Advisory |
Track CVE-2022-23530 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23530), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.