Skip to content

Security Release against ZipSlip

Latest
Compare
Choose a tag to compare
@timyates timyates released this 02 Jul 18:29
· 6 commits to master since this release

The Snyk Security Research Team at Snyk.io reached out, and pointed out that the File.unzip method was vunerable to a ZipSlip, whereby a specially crafted zip file could write files outside of the destination folder...

See https://snyk.io/research/zip-slip-vulnerability for more info

This release fixes the vulnerability