fig. 01 — GHSA-vpx7-vm66-qx8r, the advisory selected below
// advisories
GHSA-vpx7-vm66-qx8r
HIGHCVE-2020-7664
The ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.