| Version | Support |
|---|---|
| 9.x (latest) | Actively supported |
| 8.x | Not patched. Upgrade to 9.x — the JS API is compatible |
| 7.x | Security fixes only through 2027-02-19. After that, 7.x is unsupported. Stay on 7.x if you are on React Native < 0.70 until you upgrade RN. 7.x will not be deleted or unpublished. |
| < 7 | Unsupported except for critical issues |
Zip Slip / symlink fixes shipped in 9.x will be evaluated for 7.x backports. If a patch is warranted, it will be published as 7.x.y. 7.1.2 (maintenance-7 dist-tag) backports Zip Slip validation and symlink skipping for Android and iOS extract paths. 7.x stays on security-only support through the EOL date above; it is not unpublished.
Prefer GitHub Security Advisories.
You can also email the maintainer: Perry Poon <plrthink@gmail.com>.
Please do not file a public GitHub issue for an unfixed vulnerability.
In scope:
- Zip Slip / path traversal on extract
- Symlink extract that resolves outside the destination directory
- Password / crypto issues in zip/unzip
- Supply-chain issues in native deps (SSZipArchive on iOS, zip4j on Android)
- Android Zip Slip protection: 9.0.0 — extract rejects entries whose path escapes the destination.
- Android symlink extract: 9.0.2 —
unzip/unzipWithPasswordno longer materialize symlink entries.
iOS (verified in ios/RNZipArchive.mm): full and selective extract use minizip with isSafeExtractPath (Zip Slip) and skip symlink entries (shouldSkipZipEntry), matching Android #357 behavior. Full unzip no longer delegates extract to SSZipArchive.