VDB
Sign up
CRITICAL9.8

GHSA-wxj7-97fp-j53j

Exposure of Resource to Wrong Sphere in Zip-Local

Quick fix

GHSA-wxj7-97fp-j53j — zip-local: upgrade to the fixed version with the command below.

npm install zip-local@0.3.5

Details

The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/zip-local
Introduced in: 0Fixed in: 0.3.5
Fixnpm install zip-local@0.3.5

References