unzip@0.0.4

Vulnerabilities

1 via 1 paths

Dependencies

24

Source

npm

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

high severity

Arbitrary File Overwrite

  • Vulnerable module: fstream
  • Introduced through: fstream@0.1.31

Detailed paths

  • Introduced through: unzip@0.0.4 fstream@0.1.31
    Remediation: Upgrade to fstream@1.0.12.

Overview

fstream is a package that supports advanced FS Streaming for Node.

Affected versions of this package are vulnerable to Arbitrary File Overwrite. Extracting tarballs containing a hardlink to a file that already exists in the system and a file that matches the hardlink will overwrite the system's file with the contents of the extracted file.

Remediation

Upgrade fstream to version 1.0.12 or higher.

References