zip-lib is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package are vulnerable to directory traversal when extracting ZIP archives. The extraction logic does not properly validate entry paths, allowing specially crafted archive filenames containing path traversal sequences to write files outside the intended destination directory. An attacker able to supply a malicious ZIP archive could overwrite arbitrary files on the filesystem.
You are affected if you are using a version that falls within the vulnerable range.
zip-lib is vulnerable to Path Traversal in versions 0.1.0 - 1.1.2.
Upgrade the zip-lib library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant