Path Traversal in decompress
Critical severity
GitHub Reviewed
Published
Sep 3, 2020
to the GitHub Advisory Database
•
Updated Apr 18, 2023
Description
Published by the National Vulnerability Database
Apr 26, 2020
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 3, 2020
Last updated
Apr 18, 2023
Versions of
decompress
prior to 4.2.1 are vulnerable to Arbitrary File Write. The package fails to prevent extraction of files with relative paths, allowing attackers to write to any folder in the system by including filenames containing../
.Recommendation
Upgrade to version 4.2.1 or later.
References