GHSA-gj5f-73vh-wpf7
Dashboard / Vulnerabilities / GHSA-gj5f-73vh-wpf7
Summary: Withdrawn Advisory: cross-zip is vulnerable to Directory Traversal through selective use of zip/unzip operations
Details: ### Withdrawn Advisory This advisory has been withdrawn because it does not discuss a valid vulnerability. This link is maintained to preserve external references. ### Original Description All versions of the package cross-zip are vulnerable to Directory Traversal via consecutive usage of zipSync() and unzipSync () functions that allow arguments such as __dirname. An attacker can access system files by selectively doing zip/unzip operations.
References: https://nvd.nist.gov/vuln/detail/CVE-2025-11569, https://gist.github.com/mcoimbra/9ab12a6187fac41d2fa7ba594ed535ac, https://github.com/feross/cross-zip, https://github.com/feross/cross-zip/blob/eba335474e6142468bd8904f6456208db906d40d/index.js%23L94, https://security.snyk.io/vuln/SNYK-JS-CROSSZIP-6105396
Affected packages
Package
Name: cross-zip
Purl: pkg:npm/cross-zip
Affected ranges
Type: SEMVER
Events:
