Vulnerabilities/

JSZip contains Path Traversal via loadAsync

Severity:
Medium

Description

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

Recommendation

Update the jszip package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jszip
Anything's wrong? Let us know Last updated on November 18, 2024