Vulnerability GHSA-qgfr-5hqp-vrw9
Critical
CRITICAL RISK
CVSS Score: 9.8
Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
6 years ago
September 03, 2020 at 09:16 PM UTC
Path Traversal in decompress
0.1.0 - 4.2.0
0.1.0 - 4.2.0
Summary
Path Traversal in decompress
Details
Versions of decompress prior to 4.2.1 are vulnerable to Arbitrary File Write. The package fails to prevent extraction of files with relative paths, allowing attackers to write to any folder in the system by including filenames containing../.
Recommendation
Upgrade to version 4.2.1 or later.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Critical
5 hours ago
@xhmikosr/decompress: Path traversal via symlink chain
0.1.0 - 4.2.1 GHSA-hrh2-vp3x-79xf
0.1.0 - 4.2.1 GHSA-hrh2-vp3x-79xf
Medium Risk
2 months ago
decompress allows arbitrary hardlink creation during archive extraction
0.1.0 - 4.2.1 GHSA-jwp9-9v96-94mx
0.1.0 - 4.2.1 GHSA-jwp9-9v96-94mx
Critical
2 months ago
Decompress: Archive extraction can create files and links outside of the target directory
0.1.0 - 4.2.1 GHSA-mp2f-45pm-3cg9
0.1.0 - 4.2.1 GHSA-mp2f-45pm-3cg9
Medium Risk
3 months ago
decompress: Arbitrary File Write via Archive Extraction (Zip Slip)
0.1.0 - 4.2.1 GHSA-h39j-r5qq-r9mm
0.1.0 - 4.2.1 GHSA-h39j-r5qq-r9mm
Impacted packages
Timeline
Published
6 years ago
September 03, 2020 at 09:16 PM UTC
Fixed (4.2.1)
6 years ago
April 01, 2020 at 02:00 PM UTC
Last Modified
2 years ago
November 08, 2023 at 04:02 AM UTC