Executive brief
PsiTransfer is a file-sharing application that allows users to upload and download files in bulk. A path traversal vulnerability in the archive download feature enables unauthenticated attackers to upload files with directory escape sequences (like "../../../") in filenames. When a victim extracts the resulting TAR archive, malicious files can be written anywhere on their filesystem, potentially leading to remote code execution.
Technical details
This is a Zip Slip path traversal vulnerability (CWE-22/CWE-23) in PsiTransfer's archive download functionality (lib/endpoints.js). The vulnerable code directly incorporates user-controlled file metadata.name into TAR archive entry names without sanitization. An unauthenticated attacker can exploit the TUS resumable upload protocol to upload a file with path traversal sequences in its filename metadata, then trigger archive download. When a victim extracts the .tar.gz file, the malicious entries write files outside the intended directory—for example, to ~/.ssh/authorized_keys or shell configuration files—enabling arbitrary code execution. The fix (released in v2.3.1) enforces safe filename validation.
Affected products
- psi-4ward PsiTransfer <2.3.1
Timeline
- 2025-12-29: disclosed
- 2025-12-17: patched: Fix released in v2.3.1