Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[NEW VULNERABILITY] decompress-zip: GHSA-73v8-v6g4-vrpm Fix Bypass + 4 Additional Vulnerabilities

Open
#9,724 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
30/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
javascript
Domain
security

Research direction

The vulnerability is in lib/decompress-zip.js line 94, where indexOf() is used for path validation. Review the decompress-zip package source, understand the zip extraction flow, and test the bypass with a malicious zip file. The fix must properly resolve and contain paths, not just do string prefix matching. Check for similar issues in the codebase and ensure the fix addresses all listed CVEs.

Written by the indexing model from the issue text.

Description

Package Information

  • Ecosystem: npm
  • Package: decompress-zip
  • Affected versions: <= 0.3.3
  • CWE: CWE-22, CWE-770, CWE-409, CWE-345, CWE-367

Summary

The security fix in v0.3.2 for GHSA-73v8-v6g4-vrpm is INCOMPLETE and can be bypassed. Additionally, 4 new vulnerabilities were discovered.

# Vulnerability CVSS 3.1 CWE
1 Path Traversal Fix Bypass 9.1 CRITICAL CWE-22
2 Memory Exhaustion 7.5 HIGH CWE-770
3 Zip Bomb 7.5 HIGH CWE-409
4 Missing Signature Validation 5.3 MEDIUM CWE-345
5 TOCTOU Race Condition 3.1 LOW CWE-367

Critical Finding: indexOf() Bypass

File: lib/decompress-zip.js:94

if (destination.indexOf(options.path) !== 0) {
    throw new Error('You cannot extract a file outside of the target path');
}

Bypass: ../extract_pwned/evil.txt passes the check because indexOf() does STRING prefix matching, not PATH containment.

PoC

Target: /project/extract
Malicious entry: ../extract_pwned/evil.txt
Result: File written to /project/extract_pwned/evil.txt (OUTSIDE target)

Reporter

Yahya Ganbarli 
Dominant language
No language data
Stars
2.5k
Forks
772
Avg merge
3d 15h
Merged PRs (30d)
46

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from github/advisory-database

All issues in github/advisory-database

Similar issues

More Security issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.