{"id":"GHSA-gj5f-73vh-wpf7","summary":"Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations","details":"### Withdrawn Advisory\nThis advisory has been withdrawn because it does not discuss a valid vulnerability. This link is maintained to preserve external references.\n\n### Original Description\nAll versions of the package cross-zip are vulnerable to Directory Traversal via consecutive usage of zipSync() and unzipSync () functions that allow arguments such as __dirname. An attacker can access system files by selectively doing zip/unzip operations.","aliases":["CVE-2025-11569"],"modified":"2025-10-20T17:49:01Z","published":"2025-10-10T06:30:55Z","withdrawn":"2025-10-20T17:49:01Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2025-10-10T23:49:44Z","nvd_published_at":"2025-10-10T05:15:32Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11569"},{"type":"WEB","url":"https://gist.github.com/mcoimbra/9ab12a6187fac41d2fa7ba594ed535ac"},{"type":"PACKAGE","url":"https://github.com/feross/cross-zip"},{"type":"WEB","url":"https://github.com/feross/cross-zip/blob/eba335474e6142468bd8904f6456208db906d40d/index.js%23L94"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-CROSSZIP-6105396"}],"affected":[{"package":{"name":"cross-zip","ecosystem":"npm","purl":"pkg:npm/cross-zip"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"4.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-gj5f-73vh-wpf7/GHSA-gj5f-73vh-wpf7.json"}}],"schema_version":"1.9.0"}