Vulnerabilities
Vulnerable Software
Jszip Project:  >> Jszip  >> 2.6.1  Security Vulnerabilities
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.
CVSS Score
7.3
EPSS Score
0.008
Published
2023-01-29
This affects the package jszip before 3.7.0. Crafting a new zip file with filenames set to Object prototype values (e.g __proto__, toString, etc) results in a returned object with a modified prototype instance.
CVSS Score
5.3
EPSS Score
0.002
Published
2021-07-25


Contact Us

Shodan ® - All rights reserved