GHSA-vpx7-vm66-qx8r
HIGHCVE-2020-7664The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
- Affected
- < 1.0.1
- Fixed in
- 1.0.1
- Weakness
- CWE-22
- Published
- 2021-05-18
- Source
- github