CVE-2022-48285: Jszip Project Jszip

High severity, CVSS 7.3. EPSS: 1.4% chance of exploitation in the next 30 days.

loadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.

Affected products

Published 2023-01-29. Last modified 2026-06-17.