In all versions of the package github.com/unknwon/cae/tz, the ExtractTo function doesn't securely escape file paths in zip archives which include leading or non-leading "..". This allows an attacker to add or replace files system-wide.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/unknwon/cae(Go) | 0 | 1.0.1 | N/A |
CVSS Metrics