PT-2025-62913 · Crates.Io · Zip

Published

2025-03-16

·

Updated

2025-03-16

CVSS v4.0

7.3

High

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H
In the archive extraction routine of affected versions of the zip crate, symbolic links earlier in the archive are allowed to be used for later files in the archive without validation of the final canonicalized path, allowing maliciously crafted archives to overwrite arbitrary files in the file system when extracted.
For more details, see the GitHub-hosted security advisory: https://github.com/zip-rs/zip2/security/advisories/GHSA-94vh-gphv-8pm8

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2025-0168

Affected Products

Zip