magic-wormhole
Securely transfer data between computers
Activity
- Latest release
- 4mo ago
- Total releases
- 44
- Cadence
- ~2 months
- Last 12 months
- 5
Reach
- Stars
- —
Details
- License
- MIT
- First release
- Apr 10, 2015
| Version | Released | |
|---|---|---|
0.24.0
minor
| ||
0.23.0
minor
1 CVE
CVE-2026-42448
PYSEC-2026-2616
GHSA-cf92-gfcw-6v53
Jul 13, 2026
Magic Wormhole: receive, with --output pointing at an existing directory can be path-traversed
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
None
Low
None
ImpactA receiver who specifies "--output " where that output directory currently exists (as a directory). Patches0.24.0 will contain the patch WorkaroundsEnsure local target directories specified by "--output" do not already exist ResourcesPrivate email and Signal communications from a user. Magic Wormhole thanks @marduc812 Affected versions
0.23.0
Fixed in
0.24.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
CVE-2026-32116
PYSEC-2026-2615
GHSA-4g4c-mfqg-pj8r
Jul 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
Network
Low
Low
ImpactWhat kind of vulnerability is it? Who is impacted? Receiving a file ( Only the sender of the file (the party who runs PatchesHas the problem been patched? What versions should users upgrade to? The bug has been fixed in magic-wormhole 0.23.0. All users should upgrade to this version. The vulnerability first surfaced in the 0.21.0 release on 23-Oct-2025. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? As a workaround, the receiver can override the sender's filename with the ReferencesAre there any links users can visit to find out more? Incoming file transfer requests include a Many thanks to Ian McKenzie (@ikmckenz) for spotting the bug and reaching out with a fix. Affected versions
0.21.0
0.21.1
0.22.0
Fixed in
0.23.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.21.1
patch
1 CVE
CVE-2026-32116
PYSEC-2026-2615
GHSA-4g4c-mfqg-pj8r
Jul 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
Network
Low
Low
ImpactWhat kind of vulnerability is it? Who is impacted? Receiving a file ( Only the sender of the file (the party who runs PatchesHas the problem been patched? What versions should users upgrade to? The bug has been fixed in magic-wormhole 0.23.0. All users should upgrade to this version. The vulnerability first surfaced in the 0.21.0 release on 23-Oct-2025. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? As a workaround, the receiver can override the sender's filename with the ReferencesAre there any links users can visit to find out more? Incoming file transfer requests include a Many thanks to Ian McKenzie (@ikmckenz) for spotting the bug and reaching out with a fix. Affected versions
0.21.0
0.21.1
0.22.0
Fixed in
0.23.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
CVE-2026-32116
PYSEC-2026-2615
GHSA-4g4c-mfqg-pj8r
Jul 13, 2026
Magic Wormhole: "wormhole receive" allows arbitrary local file overwrite
High
Network
Low
Low
ImpactWhat kind of vulnerability is it? Who is impacted? Receiving a file ( Only the sender of the file (the party who runs PatchesHas the problem been patched? What versions should users upgrade to? The bug has been fixed in magic-wormhole 0.23.0. All users should upgrade to this version. The vulnerability first surfaced in the 0.21.0 release on 23-Oct-2025. WorkaroundsIs there a way for users to fix or remediate the vulnerability without upgrading? As a workaround, the receiver can override the sender's filename with the ReferencesAre there any links users can visit to find out more? Incoming file transfer requests include a Many thanks to Ian McKenzie (@ikmckenz) for spotting the bug and reaching out with a fix. Affected versions
0.21.0
0.21.1
0.22.0
Fixed in
0.23.0
References Updated Jul 13, 2026 · Source: OSV.dev | ||
0.20.0
minor
| ||
0.19.3
patch
| ||
0.19.2
patch
| ||
0.19.1
patch
| ||
0.19.0
minor
| ||
0.18.0
minor
| ||
0.17.0
minor
| ||
0.16.0
minor
| ||
0.15.0
minor
| ||
0.14.0
minor
| ||
0.13.0
minor
| ||
0.12.0
minor
| ||
0.11.2
patch
| ||
0.11.1
patch
| ||
0.11.0
minor
| ||
0.10.5
patch
| ||
0.10.4
patch
| ||
0.10.3
patch
| ||
0.10.2
patch
| ||
0.10.1
patch
| ||
0.10.0
minor
| ||
0.9.2
patch
| ||
0.9.1
patch
| ||
0.9.0
minor
| ||
0.8.2
patch
| ||
0.8.1
patch
| ||
0.8.0
minor
| ||
0.7.6
patch
| ||
0.7.5
patch
| ||
0.7.0
minor
| ||
0.6.3
patch
| ||
0.6.2
patch
| ||
0.6.1
patch
| ||
0.6.0
minor
| ||
0.5.0
minor
| ||
0.4.0
minor
| ||
0.3.0
minor
| ||
0.2.0
minor
| ||
0.1.0
initial
|