Vulnerabilities/

superagent vulnerable to zip bomb attacks

Severity:
Medium

Description

Affected versions of superagent do not check the post-decompression size of ZIP compressed HTTP responses prior to decompressing. This results in the package being vulnerable to a ZIP bomb attack, where an extremely small ZIP file becomes many orders of magnitude larger when decompressed.

Recommendation

Update the superagent package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
superagent
Anything's wrong? Let us know Last updated on September 08, 2023

This issue is available in SmartScanner Professional

See Pricing