RustSec logo

HistoryEditJSON (OSV)

RUSTSEC-2026-0297

unzip: archive extraction is vulnerable to path traversal (zip-slip)

Reported
Issued
Package
unzip (crates.io)
Type
Vulnerability
Categories
Keywords
#zip-slip #path-traversal #directory-traversal #arbitrary-file-write #zip
References
Patched
no patched versions
Affected Functions
Version
unzip::Unzipper::unzip
  • ^0.1.0

Description

Summary

Unzipper::unzip extracts each archive entry to a path built from the entry's raw, attacker-controlled name without any traversal check. A ZIP archive whose entry names contain ../ components (or an absolute path) can therefore cause files to be written outside the destination directory chosen by the caller — a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 / CWE-36).

Affected versions

All published versions are affected. unzip has only ever released 0.1.0 (published 2017-12-23) and appears unmaintained, so no fixed version is available.

Proof of concept

A malicious archive with a single entry named ../ESCAPED.txt extracted via Unzipper::unzip writes ESCAPED.txt one level above the destination directory.

Advisory available under CC0-1.0 license.