PT-2024-40128 · Unknown · Unzip-Stream

Published

2024-08-26

·

Updated

2024-08-26

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: unzip-stream versions prior to 0.3.2
Description: The issue allows malicious zip files to write to unauthorized paths when using the Extract() method of unzip-stream. A researcher from Google, Justin Taft, discovered this issue.
Recommendations: For versions prior to 0.3.2, update to version 0.3.2 to resolve the issue. As a temporary workaround, consider restricting the use of the Extract() method until the update is applied.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

GHSA-6JRJ-VC65-C983

Affected Products

Unzip-Stream