Lucene search

K
osvGoogleOSV:CVE-2020-12265
HistoryApr 26, 2020 - 5:15 p.m.

CVE-2020-12265

2020-04-2617:15:11
Google
osv.dev
12

AI Score

6.6

Confidence

Low

EPSS

0.006

Percentile

78.9%

The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via …/ in an archive member, when a symlink is used, because of Directory Traversal.

AI Score

6.6

Confidence

Low

EPSS

0.006

Percentile

78.9%