This site is an independent open-source project and is not affiliated with, endorsed by, or sponsored by npm, Inc. or GitHub, Inc. The name “npm” is a registered trademark of npm, Inc., used here solely to describe compatibility and reference publicly available npm package data.
Version Details and Security Vulnerabilities
📦
jszip
3.7.0
Comparision Betweeen 3.7.0 and 3.6.0
Identify the differences between the current version of the package and the previous one.
Version
Dependencies
4
4
Dev Dependencies
13
0
Peer Dependencies
13
0
Distributed Files
49
49
Unpacked Size
405.88 KB
388.37 KB
Security Vulnerabilities
Security Details
Comprehensive list of direct or transitive vulnerabilities for version 3.7.0 of the package jszip.
All Security Vulnerabilities
All the vulnerabilities related to the version 3.7.0 of the package
Summary:
JSZip contains Path Traversal via loadAsync
Details:
loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.