VDB
Sign up
HIGH7.3

GHSA-jxcc-g75x-qgw9

Calipso Arbitrary File Write via Archive Extraction (Zip Slip)

Details

This affects all versions of package calipso. It is possible for a malicious module to overwrite files on an arbitrary file system through the module install functionality.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/calipso
Introduced in: 0

No fixed version published yet for calipso (npm). Pin to a known-safe version or switch to an alternative.

References