taskcluster is vulnerable to Zip Slip
75
High Risk
Affected versions of this package are vulnerable to a zip slip vulnerability in the unzip() function, which allows attackers to write files outside the intended extraction directory by including path traversal sequences (e.g., ../) in archive entries. This issue occurs because file paths from zip entries are not properly validated before extraction. The fix adds path sanitization and validation to ensure that extracted files remain within the designated destination directory, preventing arbitrary file overwrite and potential remote code execution.
You are affected if you are using a vulnerable version of taskcluster.
taskcluster is vulnerable to Zip Slip in versions 25.3.0 - 91.1.0.
Upgrade taskcluster to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant