VDB
Sign up
MEDIUM5.3

GHSA-jg8v-48h5-wgxg

jszip Vulnerable to Prototype Pollution

Quick fix

GHSA-jg8v-48h5-wgxg — jszip: upgrade to the fixed version with the command below.

npm install jszip@3.7.0

Details

This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g `__proto__`, `toString`, etc) results in a returned object with a modified prototype instance.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/jszip
Introduced in: 3.0.0Fixed in: 3.7.0
Fixnpm install jszip@3.7.0
npm/jszip
Introduced in: 0Fixed in: 2.7.0
Fixnpm install jszip@2.7.0

References