Headline
GHSA-6jrj-vc65-c983: unzip-stream allows Arbitrary File Write via artifact extraction
Impact
When using the Extract()
method of unzip-stream, malicious zip files were able to write to paths they shouldn’t be allowed to.
Patches
Fixed in 0.3.2
References
- https://snyk.io/research/zip-slip-vulnerability
- https://github.com/mhr3/unzip-stream/compare/v0.3.1…v0.3.2
Credits
Justin Taft from Google
unzip-stream allows Arbitrary File Write via artifact extraction
High severity GitHub Reviewed Published Aug 25, 2024 in mhr3/unzip-stream • Updated Aug 26, 2024