VYPR

npm package

zip-local

pkg:npm/zip-local

Vulnerabilities (1)

  • CVE-2021-23484Jan 28, 2022
    affected < 0.3.5fixed 0.3.5

    The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.