PT-2026-65386 · Libzip · Libzip

·

CVE-2026-17524

·

Published

2026-07-28

·

Updated

2026-07-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions zip-lib versions prior to 1.1.0
Description An issue exists in the caching mechanism for path validation during the extraction process, allowing for Directory Traversal. This occurs because the security function isOutsideTargetFolder() only checks and caches the path status when the initial directory symlink is created during the first extraction, enabling an attacker to bypass security checks intended to prevent files from being written outside the target folder.
Recommendations Update zip-lib to version 1.1.0 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-17524

Affected Products

Libzip