{"id":"GHSA-wxj7-97fp-j53j","summary":"Exposure of Resource to Wrong Sphere in Zip-Local","details":"The package zip-local before 0.3.5 are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) which can lead to an extraction of a crafted file outside the intended extraction directory.","aliases":["CVE-2021-23484","SNYK-JS-ZIPLOCAL-2327477"],"modified":"2026-09-10T03:49:12.296259937Z","published":"2022-02-01T00:46:01Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2022-01-31T19:55:36Z","nvd_published_at":"2022-01-28T22:15:00Z","cwe_ids":["CWE-29","CWE-668"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-23484"},{"type":"WEB","url":"https://github.com/Mostafa-Samir/zip-local/commit/6bb9b59733df379ac168aa705790bd8339b4bf9b"},{"type":"WEB","url":"https://github.com/Mostafa-Samir/zip-local/commit/949446a95a660c0752b1db0c654f0fd619ae6085"},{"type":"PACKAGE","url":"https://github.com/Mostafa-Samir/zip-local"},{"type":"WEB","url":"https://github.com/Mostafa-Samir/zip-local/blob/master/main.js%23L365"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-ZIPLOCAL-2327477"}],"affected":[{"package":{"name":"zip-local","ecosystem":"npm","purl":"pkg:npm/zip-local"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.3.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-wxj7-97fp-j53j/GHSA-wxj7-97fp-j53j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}