Junglewise Threat Intelligence

CVE-2026-13723: Develar app-builder arbitrary file overwrite via Unicode collision in zipx.Unzip

CVE-2026-13723 · Severity: info · CVSS 0 · Published 2026-07-29

Technologies: Develar App Builder.

Executive brief

Develar app-builder is a tool used to package and distribute software, particularly within the Electron ecosystem. A security flaw in how it handles compressed ZIP files on macOS allows a malicious archive to overwrite files anywhere on the user's computer that the user has permission to access. This could lead to the corruption of important system files, loss of data, or the execution of unauthorized code if critical application files are replaced.

Technical details

A vulnerability exists in the `zipx.Unzip` extraction routine of Develar's app-builder (up to version 4.2.0) due to improper path validation on macOS APFS volumes. The issue stems from a combination of CWE-22 (Path Traversal) and CWE-59 (Link Following) where the application fails to perform canonical Unicode normalization before validating paths. Because APFS treats certain Unicode-equivalent characters as identical (e.g., 'ß' and 'ss'), an attacker can craft a ZIP archive containing a symlink (e.g., named 'ss') pointing to a sensitive system file, followed by a regular file using a colliding Unicode name (e.g., 'ß'). During extraction, the second file write follows the previously created symlink, overwriting the target file. A community-provided fix involves enforcing directory containment for symlinks and using the O_NOFOLLOW flag during file writes.

Affected products

  • Develar app-builder <= 4.2.0

Timeline

  • 2026-05-27: other: Vendor notified by CERT/CC
  • 2026-07-08: patched: Community pull request with fix submitted to GitHub repository
  • 2026-07-29: disclosed: Vulnerability publicly disclosed by CERT/CC and NVD

References