An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
{ "last_known_affected_version_range": "<= 3.3.7" }