PT-2026-96198 · Crates.Io · Unzip
Published
2026-09-09
·
Updated
2026-09-09
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Summary
Unzipper::unzip extracts each archive entry to a path built from the entry's
raw, attacker-controlled name without any traversal check. A ZIP archive whose
entry names contain ../ components (or an absolute path) can therefore cause
files to be written outside the destination directory chosen by the caller —
a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 /
CWE-36).Affected versions
All published versions are affected.
unzip has only ever released 0.1.0
(published 2017-12-23) and appears unmaintained, so no fixed version is
available.Proof of concept
A malicious archive with a single entry named
../ESCAPED.txt extracted via
Unzipper::unzip writes ESCAPED.txt one level above the destination directory. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Unzip