Lucene search

K
nodejsSnyk security teamNODEJS:680
HistoryAug 03, 2018 - 3:08 p.m.

Arbitrary File Write via Archive Extraction

2018-08-0315:08:43
snyk security team
www.npmjs.com
541

0.001 Low

EPSS

Percentile

36.4%

Overview

Versions of unzipper before 0.8.13 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt for example).

Recommendation

Update to version 0.3.18 or later.

References

CPENameOperatorVersion
unzipperlt0.8.13