unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "0.8.13"
}
],
"cpes": [
"cpe:2.3:a:unzipper_project:unzipper:*:*:*:*:*:node.js:*:*"
],
"source": "CPE_RANGE",
"vendor_product": "unzipper_project:unzipper"
},
{
"extracted_events": [
{
"fixed": "0.8.13"
}
],
"source": "DESCRIPTION"
}
]
}