Description
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Recommendation
Update the jszip package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.8.0
- Patched version(s): 3.8.0
References
- GHSA-36fh-84j7-cv5h
- www.mend.io
- exchange.xforce.ibmcloud.com
- security.netapp.com
- CVE-2022-48285
- CWE-22
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
- fast-uri vulnerable to path traversal via percent-encoded dot segments - CVE-2026-6321
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606
- i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns - CVE-2026-41691
You might also like:
- Tags:
- npm
- jszip
Anything's wrong? Let us know Last updated on November 18, 2024


