Intel

AIKIDO-2026-10202

zip-lib is vulnerable to Path Traversal

Path Traversal Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2026

65

Medium Risk

This Affects:

JSzip-lib
0.1.0 - 1.1.2
Fixed in 1.2.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to directory traversal when extracting ZIP archives. The extraction logic does not properly validate entry paths, allowing specially crafted archive filenames containing path traversal sequences to write files outside the intended destination directory. An attacker able to supply a malicious ZIP archive could overwrite arbitrary files on the filesystem.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

zip-lib is vulnerable to Path Traversal in versions 0.1.0 - 1.1.2.

How to fix this

Upgrade the zip-lib library to the patch version.