Loading HuntDB...

GHSA-884w-698f-927f

GitHub Security Advisory

Arbitrary File Write via Archive Extraction in unzipper

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Versions of `unzipper` before 0.8.13 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (`../../file.txt` for example).

## Recommendation

Update to version 0.3.18 or later.

Affected Packages

npm unzipper
Affected versions: 0 (fixed in 0.8.13)

Related CVEs

Key Information

GHSA ID
GHSA-884w-698f-927f
Published
July 27, 2018 5:06 PM
Last Modified
September 11, 2023 10:41 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
unzipper
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 13, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.