CyberRota Analysis
This vulnerability has an unknown severity rating. It may be remotely exploitable.
CVE
CVE-2025-9118
Severity
UNKNOWN
CVSS
N/A
EPSS
0.65%
Original NVD Description
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.