Description
All versions of the package cross-zip are vulnerable to Directory Traversal via consecutive usage of zipSync() and unzipSync () functions that allow arguments such as __dirname. An attacker can access system files by selectively doing zip/unzip operations.
Problem types
Credits
Miguel Coimbra
References
security.snyk.io/vuln/SNYK-JS-CROSSZIP-6105396
gist.github.com/mcoimbra/9ab12a6187fac41d2fa7ba594ed535ac
github.com/...74e6142468bd8904f6456208db906d40d/index.js#L94