Skip to content

Arbitrary File Write via artifact extraction

High
mhr3 published GHSA-6jrj-vc65-c983 Aug 25, 2024

Package

npm unzip-stream (npm)

Affected versions

< 0.3.2

Patched versions

0.3.4

Description

Impact

When using the Extract() method of unzip-stream, malicious zip files were able to write to paths they shouldn't be allowed to.

Patches

Fixed in 0.3.4

References

Credits

Justin Taft from Google

Severity

High

CVE ID

CVE-2024-42471

Weaknesses