Vulnerability GHSA-qgfr-5hqp-vrw9

Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
6 years ago
September 03, 2020 at 09:16 PM UTC
Path Traversal in decompress
0.1.0 - 4.2.0
0.1.0 - 4.2.0

Summary

Path Traversal in decompress

Details

Versions of decompress prior to 4.2.1 are vulnerable to Arbitrary File Write. The package fails to prevent extraction of files with relative paths, allowing attackers to write to any folder in the system by including filenames containing../.

Recommendation

Upgrade to version 4.2.1 or later.

Impacted packages

Timeline

Published
6 years ago
September 03, 2020 at 09:16 PM UTC
Fixed (4.2.1)
6 years ago
April 01, 2020 at 02:00 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:02 AM UTC