All the vulnerabilities related to the version 0.4.4 of the package
Arbitrary File Write in adm-zip
Versions of adm-zip
before 0.4.9 are vulnerable to arbitrary file write when used to extract a specifically crafted archive that contains path traversal filenames (../../file.txt
for example).
Update to version 0.4.9 or later.