Executive brief
An application that allows authenticated users to upload archive files fails to validate that extracted files remain in the intended destination directory. An attacker can craft a malicious archive with entries that traverse outside the target directory, allowing them to write files anywhere on the system with application privileges. This could lead to data corruption, configuration tampering, or system compromise.
Technical details
This is a path traversal vulnerability in archive extraction logic (CWE-22). The vulnerable component accepts file uploads from authenticated users and automatically extracts archive contents without validating extracted file paths. An attacker can craft an archive with relative path entries (e.g., `../../etc/config`) that cause the extraction process to write files outside the intended directory. No user interaction beyond uploading the archive is required; authentication is a prerequisite. An attacker can inject arbitrary files into the system, potentially overwriting configuration files, application data, or other critical files with the privileges of the extraction process. No patch information is available in the advisory.
Affected products
- <UNKNOWN>
Timeline
- 2026-09-11: disclosed