Medium severity5.5NVD Advisory· Published Jul 25, 2018· Updated Jun 17, 2026
CVE-2018-1002204
CVE-2018-1002204
Description
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
adm-zipnpm | < 0.4.11 | 0.4.11 |
Affected products
3- node.js/adm-zipv5Range: unspecified
Patches
Vulnerability mechanics
References
10- github.com/cthackers/adm-zip/commit/62f64004fefb894c523a7143e8a88ebe6c84df25nvdIssue TrackingPatchThird Party AdvisoryWEB
- github.com/cthackers/adm-zip/pull/212nvdExploitIssue TrackingPatchThird Party AdvisoryWEB
- snyk.io/research/zip-slip-vulnerabilitynvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/npm:adm-zip:20180415nvdExploitThird Party AdvisoryWEB
- www.securityfocus.com/bid/107001nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-3v6h-hqm4-2rg6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1002204ghsaADVISORY
- hackerone.com/reports/362118ghsaWEB
- www.npmjs.com/advisories/681ghsaWEB
- www.npmjs.com/advisories/994ghsaWEB
News mentions
0No linked articles in our index yet.