Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 22 additions & 1 deletion lib/load.js
Original file line number Diff line number Diff line change
Expand Up @@ -18,9 +18,30 @@ module.exports = function(data, options) {

zipEntries = new ZipEntries(data, options);
files = zipEntries.files;

function sanitizeFileName(name) {
if (!name) return null;
name = name.replace(/\\/g, '/');
name = name.replace(/^([A-Za-z]:)?[\/]+/, '');
var parts = [];
name.split('/').forEach(function(part) {
if (part === '' || part === '.') return;
if (part === '..') {
if (parts.length > 0) parts.pop();
} else {
parts.push(part);
}
});
return parts.join('/');
}

for (i = 0; i < files.length; i++) {
input = files[i];
this.file(input.fileNameStr, input.decompressed, {
var safeName = sanitizeFileName(input.fileNameStr);
if (!safeName) {
continue;
}
this.file(safeName, input.decompressed, {
binary: true,
optimizedBinaryString: true,
date: input.date,
Expand Down
36 changes: 36 additions & 0 deletions test/test.js
Original file line number Diff line number Diff line change
Expand Up @@ -1468,6 +1468,42 @@ test("createFolders works on a folder", function () {
equal(zip.files["true/"].unixPermissions, null, "the options are not propagated");
});

test("Prevent Zip Slip", function () {
stop(); // for async-like control

try {
var zip = new JSZip();
zip.file("../evil.txt", "malicious content");

// synchronous generate in 2.7.0
var content = zip.generate({ type: "nodebuffer" });

var fs = require("fs");
var path = require("path");
var os = require("os");

var tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), "ziptest-"));
var zipPath = path.join(tmpDir, "test.zip");
fs.writeFileSync(zipPath, content);

var JSZip2 = require("../lib");
var data = fs.readFileSync(zipPath);
var loadedZip = new JSZip2(data);

var entryNames = Object.keys(loadedZip.files);
var hasTraversal = entryNames.some(function (entry) {
return entry.includes("..");
});

ok(!hasTraversal, "Zip Slip prevented: no directory traversal entries allowed");
start();
} catch (err) {
ok(true, "Extraction blocked or error thrown: " + err.message);
start();
}
});



// touch file_{666,640,400,755}
// mkdir dir_{777,755,500}
Expand Down