You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
unzip-stream allows Arbitrary File Write via artifact extraction
High severity
GitHub Reviewed
Published
Aug 25, 2024
in
mhr3/unzip-stream
•
Updated Aug 26, 2024
Impact
When using the
Extract()
method of unzip-stream, malicious zip files were able to write to paths they shouldn't be allowed to.Patches
Fixed in 0.3.2
References
Credits
Justin Taft from Google
References