Copy link to clipboard
Copied
Dear Adobe Support Team,
I am reaching out to report an issue related to ZIP file validation in your software packages and to request your assistance in addressing it.
As part of a personal project aimed at mitigating ZIP-based vulnerabilities such as ZIP Slip, ZIP Bombs, and ZIP Filename Spoofing. I’ve implemented a set of validation tools to test ZIP and nested ZIP file structures. This effort is part of a broader goal to ensure software integrity and enhance security.
During testing, I prioritized software packages that commonly use ZIP for distribution. While the vast majority passed my validation checks, I encountered issues with Adobe’s package. Specifically, I identified two ZIP files that fail sanitization due to structural issues:
* 1\x64\js\node_modules\thread-stream\test\ts-commonjs-default-export.zip
* 1\x64\js\node_modules\thread-stream\test\dir with spaces\test-package.zip
These files appear to reside within test directories and do not seem essential to the runtime functionality of your software. However, their presence is currently blocking automated deployment validation in my environment.
To help resolve this issue and support secure deployment, I kindly request that Adobe consider one of the following actions for future package distributions:
1. Remove non-essential test ZIP files from distribution packages if they are not critical to software operation.
2. Ensure all included ZIP files are valid and conform to standard ZIP specifications, so they can pass common validation tools.
I understand that managing large-scale software packages is complex, and I sincerely appreciate the high standards Adobe maintains across its offerings. My intention is to collaborate toward a solution that ensures both security and functionality.
If you require more technical details about the validation process or the tools I am using, I would be happy to provide them. Please don’t hesitate to reach out if you’d like to discuss this further.
Thank you for your time and attention. I look forward to your response.
Copy link to clipboard
Copied
Where does InDesign create any ZIP file. After packaging I have to use a different program to create a ZIP.
Get ready! An upgraded Adobe Community experience is coming in January.
Learn more