Description
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
Recommendation
Update the jszip package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.8.0
- Patched version(s): 3.8.0
References
Could your website be exposed too?
SmartScanner can check your website for JSZip contains Path Traversal via loadAsync and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Agnai File Disclosure Vulnerability: JSON via Path Traversal - CVE-2024-47170
- fast-uri vulnerable to path traversal via percent-encoded dot segments - CVE-2026-6321
- Rollup 4 has Arbitrary File Write via Path Traversal - CVE-2026-27606
- i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns - CVE-2026-41691
You might also like:
See something that needs correcting? Let us knowUpdated November 18, 2024


