| Version | Support |
|---|---|
| 9.x (latest) | Actively supported |
| 8.x | Not patched. Upgrade to 9.x — the JS API is compatible |
| 7.x | Security fixes only through 2027-02-19. After that, 7.x is unsupported. Stay on 7.x if you are on React Native < 0.70 until you upgrade RN. 7.x will not be deleted or unpublished. |
| < 7 | Unsupported except for critical issues |
Zip Slip / symlink fixes shipped in 9.x will be evaluated for 7.x backports. If a patch is warranted, it will be published as 7.x.y. 7.1.3 (maintenance-7 dist-tag) is the 7.x release to install: it includes the Zip Slip / symlink backport from 7.1.2 and the Android compile fix for compressionLevel (#390). 7.1.2 has the security backport but does not compile on Android. 7.x stays on security-only support through the EOL date above; it is not unpublished.
Prefer GitHub Security Advisories.
You can also email the maintainer: Perry Poon <plrthink@gmail.com>.
Please do not file a public GitHub issue for an unfixed vulnerability.
In scope:
- Zip Slip / path traversal on extract
- Symlink extract that resolves outside the destination directory
- Password / crypto issues in zip/unzip
- Supply-chain issues in native deps (SSZipArchive on iOS, zip4j on Android)
- Android Zip Slip protection: 9.0.0 — extract rejects entries whose path escapes the destination.
- Android symlink extract: 9.0.2 —
unzip/unzipWithPasswordno longer materialize symlink entries.
iOS (verified in ios/RNZipArchive.mm): full and selective extract use minizip with isSafeExtractPath (Zip Slip) and skip symlink entries (shouldSkipZipEntry), matching Android #357 behavior. Full unzip no longer delegates extract to SSZipArchive.