@capgo/capacitor-updater is vulnerable to Path Traversal
47
Medium Risk
The Capacitor update plugin extracts downloaded update archives and processes manifest entries on Android and iOS without validating that target paths stay inside the bundle directory. A crafted update archive or manifest entry can cause the plugin to write files outside the intended bundle directory on the device. The fix introduces canonical-path containment checks for ZIP entries and manifest paths, rejects absolute, empty, backslash, and null-byte paths.
You are affected if you are using a version that falls within the vulnerable range.
@capgo/capacitor-updater is vulnerable to Path Traversal in versions 5.0.0 - 8.47.2.
Upgrade the @capgo/capacitor-updater library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant