Junglewise Threat Intelligence

unzip-stream arbitrary file write via path traversal

Severity: low · CVSS 3.1 · Published 2024-08-26

Vendors: npm.

Executive brief

unzip-stream is a Node.js library used to extract ZIP files. A vulnerability allows attackers to extract malicious ZIP archives that write files to arbitrary locations outside the intended extraction directory, potentially overwriting system or application files. This could lead to code execution, data corruption, or service disruption if untrusted ZIP files are processed.

Technical details

The Extract() method in unzip-stream fails to properly validate and sanitize file paths from ZIP archive entries, allowing path traversal attacks (CWE-22). Malicious ZIP files can include specially crafted paths containing directory traversal sequences (e.g., ../../../) that resolve to locations outside the restricted extraction directory. The vulnerability requires network or local access to supply a malicious ZIP file to the application, but no authentication is needed and extraction can occur without user interaction. An attacker can write arbitrary files to any location writable by the application process, potentially achieving remote code execution. The issue is patched in versions 0.3.2 and later (with additional hardening in 0.3.4).

Affected products

  • unzip-stream unzip-stream before 0.3.2

Timeline

  • 2024-08-26: disclosed
  • 2024-08-26: patched: Fixed in version 0.3.2 (further hardening in 0.3.4)

References