Junglewise Threat Intelligence

unzip library path traversal in archive extraction

Severity: info · Published 2026-09-09

Technologies: Unzip. Vendors: crates.io.

Executive brief

The unzip Rust library extracts ZIP archive contents without validating that entry names stay within the intended destination directory. An attacker can create a malicious ZIP file with entries named using path traversal sequences (like `../`) to write files outside the target folder, potentially overwriting system files or injecting code.

Technical details

The Unzipper::unzip function builds output file paths directly from attacker-controlled ZIP entry names without sanitization or traversal checks, enabling arbitrary file writes via zip-slip (CWE-22/CWE-23/CWE-36). Exploitation requires an application to extract a crafted ZIP archive. The library is unmaintained with no patched versions available.

Affected products

  • unzip 0.1.0

Timeline

  • 2026-09-09: disclosed
  • 2026-09-21: advisory

References

Related threats