在 peerigon 的 unzip-crx 和 unzip-crx-3 版本(最高至 0.2.0)中发现了一个漏洞。该漏洞影响组件“Archive Extraction”中 dist/index.js 文件里的 unzip 函数。通过操纵参数 destination,可导致路径遍历(path traversal)漏洞。该攻击仅能在本地执行。相关利用代码已公开,并可被实际使用。项目方已通过问题报告早期获知该问题,但截至目前尚未作出回应。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| peerigon | unzip-crx | 0.1 |
affected |
0.2.0 |
affected | ||
| peerigon | unzip-crx-3 | 0.1 |
affected |
0.2.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| peerigon | unzip-crx | 0.1 |
cpe:2.3:a:peerigon:unzip-crx:*:*:*:*:*:*:*:*
|
|
| peerigon | unzip-crx-3 | 0.1 |
cpe:2.3:a:peerigon:unzip-crx-3:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet