Skip to content

Vulnerability Report: Arbitrary File Write via Symlinks in extract-zip #149

@lilify-jp

Description

@lilify-jp

@max-mapper

I've removed the technical details from this issue for responsible disclosure.

This is a high-severity symlink validation vulnerability.

Could you please contact me to discuss this privately? I have:

  • Full technical analysis
  • Working proof-of-concept
  • Suggested patch

How would you prefer to receive the details?

  • GitHub discussions
  • Email
  • Other secure channel

Thank you for your attention to this matter.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions