Executive brief
Zio is a .NET library used for file system abstraction. A vulnerability in its 'SubFileSystem' component allows a user to bypass directory restrictions and access the root of the parent file system. While this does not allow reading or writing individual files, it could allow an attacker to see directory structures and metadata they should not have access to.
Technical details
A path traversal vulnerability exists in Zio.UPath.ValidateAndNormalize and Zio.FileSystems.SubFileSystem. The ValidateAndNormalize function contains a trailing slash optimization that strips the final separator and returns early if certain conditions are met. When an input path like '/../' is provided, the function returns '/..' before the parent directory ('..') resolution logic can execute. When this unresolved path is processed by SubFileSystem.ConvertPathToDelegate, it resolves to the root of the parent filesystem instead of the intended sub-path. This bypass is limited to directory-level operations (e.g., checking directory existence) and does not extend to file read/write operations. The issue is fixed in version 0.22.2.
Affected products
- xoofx Zio <= 0.22.1
Timeline
- 2026-04-17: disclosed
- 2026-04-18: advisory
- 2026-04-18: patched: Fixed in version 0.22.2