adm-zip
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting adm-zippage 1 of 1
- CVE-2018-1002204MEDIUMCVSS 5.5EG 5.5✓ Fixed in 0.4.112018-07-25
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known a…
- CVE-2026-39244HIGHCVSS 7.5EG 7.5✓ Fixed in 0.6.02026-07-10
adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js line 103, Buffer.alloc(_centralHeader.size) allocates memory based on the declared uncompress…
Check whether adm-zip is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for adm-zip CVEs against the assets you own.
Start Free Scan →