Severity
8.6
High severity
Details
- CVSS score
- 8.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE ID
Overview
About vulnerability
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like ‘../../../../etc/passwd’, extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.Details
- Affected product:
- appium-execute-driver-plugin , axe-core-npm , browsers , chromedriver , electron , expect-webdriverio , extract-zip , lighthouse , netlify-dev , netlify-functions-dev , netlify-nuxt , netlify-vite-plugin , netlify-vite-plugin-tanstack-start , netlify/functions , playwright-core , playwright-test , puppeteer , storybook , subfont , vitest-webdriverio , wdio-allure-reporter , wdio-appium-service , wdio-browserstack-service , wdio-cli , wdio-cucumber-framework , wdio-dot-reporter , wdio-globals , wdio-junit-reporter , wdio-local-runner , wdio-mocha-framework , wdio-runner , wdio-spec-reporter , web , web-test-runner-browserstack , web-test-runner-saucelabs , webdriverio
- Affected packages:
- extract-zip @ 2.0.1 (+308 more)