RUSTSEC-2026-0297
`unzip`: archive extraction is vulnerable to path traversal (zip-slip)
Details
### Summary
`Unzipper::unzip` extracts each archive entry to a path built from the entry's **raw, attacker-controlled name** without any traversal check. A ZIP archive whose entry names contain `../` components (or an absolute path) can therefore cause files to be written **outside** the destination directory chosen by the caller — a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 / CWE-36).
### Affected versions
All published versions are affected. `unzip` has only ever released `0.1.0` (published 2017-12-23) and appears unmaintained, so **no fixed version is available**.
### Proof of concept
A malicious archive with a single entry named `../ESCAPED.txt` extracted via `Unzipper::unzip` writes `ESCAPED.txt` one level above the destination directory.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0No fixed version published yet for unzip. Pin to a known-safe version or switch to an alternative.