CVE-2025-9118: exploitation status and patch state
CVE-2025-9118 · EPSS 1%
A path traversal vulnerability in the NPM package installation process of Google Cloud Dataform allows a remote attacker to read and write files in other customers' repositories via a maliciously crafted package.json file.
Is CVE-2025-9118 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.