@appium/support is vulnerable to Path Traversal
65
Medium Risk
The @appium/support package extracts ZIP archives while validating destination entry names without resolving symbolic links. A crafted archive can include a symlink entry that points outside the extraction directory. Because the name checks pass, the extractor follows the symlink and writes the file to an arbitrary location outside the intended extraction root. The fix blocks extraction of symlinks whose targets escape the destination directory.
You are affected if you are using a version that falls within the vulnerable range and you extract ZIP archives whose contents are untrusted.
@appium/support is vulnerable to Path Traversal in versions 0.0.1 - 7.2.5.
Upgrade the @appium/support library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant