CRITICAL 9.8 npm
Path Traversal in decompress
GHSA-qgfr-5hqp-vrw9 · CVE-2020-12265
Published · Modified
Description
Versions of decompress prior to 4.2.1 are vulnerable to Arbitrary File Write. The package fails to prevent extraction of files with relative paths, allowing attackers to write to any folder in the system by including filenames containing../.
Recommendation
Upgrade to version 4.2.1 or later.
Ready to move
Start Securing
Free, no credit card | First findings in minutes