Unzipper::unzip extracts each archive entry to a path built from the entry's
raw, attacker-controlled name without any traversal check. A ZIP archive whose
entry names contain ../ components (or an absolute path) can therefore cause
files to be written outside the destination directory chosen by the caller —
a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 /
CWE-36).
All published versions are affected. unzip has only ever released 0.1.0
(published 2017-12-23) and appears unmaintained, so no fixed version is
available.
A malicious archive with a single entry named ../ESCAPED.txt extracted via
Unzipper::unzip writes ESCAPED.txt one level above the destination directory.
{
"license": "CC0-1.0"
}