GHSA-gj5f-73vh-wpf7

Suggest an improvement
Source
https://github.com/advisories/GHSA-gj5f-73vh-wpf7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-gj5f-73vh-wpf7/GHSA-gj5f-73vh-wpf7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gj5f-73vh-wpf7
Aliases
  • CVE-2025-11569
Withdrawn
2025-10-20T17:49:01Z
Published
2025-10-10T06:30:55Z
Modified
2025-10-20T17:49:01Z
Summary
Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
Details

Withdrawn Advisory

This advisory has been withdrawn because it does not discuss a valid vulnerability. This link is maintained to preserve external references.

Original Description

All versions of the package cross-zip are vulnerable to Directory Traversal via consecutive usage of zipSync() and unzipSync () functions that allow arguments such as __dirname. An attacker can access system files by selectively doing zip/unzip operations.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-10T23:49:44Z",
    "nvd_published_at": "2025-10-10T05:15:32Z",
    "severity": "LOW"
}
References

Affected packages

npm / cross-zip

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-gj5f-73vh-wpf7/GHSA-gj5f-73vh-wpf7.json"