Vulnerabilities/

PsiTransfer has Zip Slip Path Traversal via TAR Archive Download

Severity:
High

Description

A Zip Slip vulnerability in PsiTransfer allows an unauthenticated attacker to upload files with path traversal sequences in the filename (e.g. ../../../.ssh/authorized_keys). When a victim downloads the bucket as a .tar.gz archive and extracts it, malicious files are written outside the intended directory, potentially leading to RCE.

Recommendation

Update the psitransfer package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
psitransfer
Anything's wrong? Let us know Last updated on December 30, 2025