Executive brief
The unzip Rust library extracts ZIP archive contents without validating that entry names stay within the intended destination directory. An attacker can create a malicious ZIP file with entries named using path traversal sequences (like `../`) to write files outside the target folder, potentially overwriting system files or injecting code.
Technical details
The Unzipper::unzip function builds output file paths directly from attacker-controlled ZIP entry names without sanitization or traversal checks, enabling arbitrary file writes via zip-slip (CWE-22/CWE-23/CWE-36). Exploitation requires an application to extract a crafted ZIP archive. The library is unmaintained with no patched versions available.
Affected products
- unzip 0.1.0
Timeline
- 2026-09-09: disclosed
- 2026-09-21: advisory