ZipSlip issue when use fsutil package to unzip files. When users use fsutil.Unzip to unzip zip files from a malicious attacker, they may be vulnerable to path traversal.
It has been fixed in v0.6.0, Please upgrade version to v0.6.0 or above.
No, users have to upgrade version.
{ "nvd_published_at": "2023-03-07T18:15:00Z", "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2023-03-07T20:37:09Z" }