GHSA-884w-698f-927f
GitHub Security Advisory
Arbitrary File Write via Archive Extraction in unzipper
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Versions of `unzipper` before 0.8.13 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (`../../file.txt` for example).
## Recommendation
Update to version 0.3.18 or later.
Affected Packages
npm
unzipper
Affected versions:
0
(fixed in 0.8.13)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 13, 2025 6:30 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.