Skip to content

[GHSA-gj5f-73vh-wpf7] cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations#6326

Closed
MarshallOfSound wants to merge 1 commit intoMarshallOfSound/advisory-improvement-6326from
MarshallOfSound-GHSA-gj5f-73vh-wpf7
Closed

[GHSA-gj5f-73vh-wpf7] cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations#6326
MarshallOfSound wants to merge 1 commit intoMarshallOfSound/advisory-improvement-6326from
MarshallOfSound-GHSA-gj5f-73vh-wpf7

Conversation

@MarshallOfSound
Copy link

Updates

  • Affected products
  • CVSS v4
  • Severity

Comments
This GHSA is absolute nonsense, the entire premise of this NPM module is "given a path, make me a zip" and the GHSA is claiming that the API itself is directory traversal. i.e. the fact they can pass in a path and have it generate a zip is directory traversal. By that logic the cat, ls, cd, tail, zip commands are also all vulnerable... Absolutely absurd....

@github-actions github-actions bot changed the base branch from main to MarshallOfSound/advisory-improvement-6326 October 16, 2025 23:55
@github-actions github-actions bot deleted the MarshallOfSound-GHSA-gj5f-73vh-wpf7 branch October 16, 2025 23:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant