HIGH7.1
RUSTSEC-2026-0307
`uncbv`: archive extraction is vulnerable to path traversal (zip-slip)
Details
### Summary
`uncbv extract` writes each archive entry to `output_dir.join(entry_filename)` using the filename stored in the archive with no check for `..` components or absolute paths. A malicious `.cbv` / `.cbz` archive whose entry name contains `../` (or an absolute path) can therefore cause files to be written outside the output directory chosen by the user. This is a "zip-slip" / directory-traversal arbitrary file write (CWE-22).
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/uncbv
Introduced in:
0.0.0-0Fixed in: 0.3.1Upgrade uncbv to 0.3.1 or newer (ecosystem crates.io).