VDB
Sign up

RUSTSEC-2026-0297

`unzip`: archive extraction is vulnerable to path traversal (zip-slip)

Details

### Summary

`Unzipper::unzip` extracts each archive entry to a path built from the entry's **raw, attacker-controlled name** without any traversal check. A ZIP archive whose entry names contain `../` components (or an absolute path) can therefore cause files to be written **outside** the destination directory chosen by the caller — a "zip-slip" / directory-traversal arbitrary file write (CWE-22 / CWE-23 / CWE-36).

### Affected versions

All published versions are affected. `unzip` has only ever released `0.1.0` (published 2017-12-23) and appears unmaintained, so **no fixed version is available**.

### Proof of concept

A malicious archive with a single entry named `../ESCAPED.txt` extracted via `Unzipper::unzip` writes `ESCAPED.txt` one level above the destination directory.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/unzip
Introduced in: 0.0.0-0

No fixed version published yet for unzip. Pin to a known-safe version or switch to an alternative.

References