Lack of data validation - Path Traversal In decompress
Description
Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip). It is possible to bypass the security measures provided by decompress and conduct ZIP path traversal through symlinks.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
npm | 4.2.1 | ||
npm | - |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3.