Skip to content
Discussion options

You must be logged in to vote

zip.js does not unzip files recursively. That already reduces the attack surface quite a bit. For example, you can open the zip file provided here: https://github.com/iamtraction/ZOD without crashing your browser with this demo: https://gildas-lormeau.github.io/zip.js/demos/demo-read-file.html.

Can you think of any other types of attack?

Replies: 4 comments 3 replies

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by jlarmstrongiv
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
3 replies
@gildas-lormeau
Comment options

@jlarmstrongiv
Comment options

@gildas-lormeau
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants