A flaw was found in the decompression function of registry-support. This issue can be triggered if an unauthenticated remote attacker tricks a user into parsing a devfile which uses the `parent` or `plugin` keywords. This could download a malicious archive and cause the cleanup process to overwrite or delete files outside of the archive, which should not be allowed.
CVE ID: CVE-2024-1485
EPSS Score: 0.11% (probability of being exploited)
EPSS Percentile: 45.23% (scored less or equal to compared to others)
EPSS Date: 2025-03-07 (when was this score calculated)