Junglewise Threat Intelligence

unzip library unmaintained with known path-traversal vulnerability

Severity: info · Published 2026-09-21

Vendors: crates.io.

Executive brief

The unzip Rust library, which extracts files from ZIP archives, has not been updated since its initial release in 2017 and is no longer maintained. It contains a known path-traversal flaw ("zip-slip") that allows attackers to extract files outside their intended directory, potentially overwriting system files or installing malware. No fixes will be issued for this vulnerability, making any application using this library vulnerable to exploitation.

Technical details

The unzip crate is unmaintained with a single release (0.1.0 from December 2017) and contains an unpatched path-traversal vulnerability in ZIP file extraction. The vulnerability allows an attacker to craft a malicious ZIP archive with directory traversal sequences (e.g., "../") in filenames, enabling extraction outside the intended directory and potentially achieving code execution or data destruction. No patch is available; migration to actively maintained alternatives such as the zip crate is required.

Affected products

  • Rust crates.io unzip 0.1.0

Timeline

  • 2026-09-21: disclosed

References

Related threats