VDB
Sign up
HIGH7.1

RUSTSEC-2026-0307

`uncbv`: archive extraction is vulnerable to path traversal (zip-slip)

Details

### Summary

`uncbv extract` writes each archive entry to `output_dir.join(entry_filename)` using the filename stored in the archive with no check for `..` components or absolute paths. A malicious `.cbv` / `.cbz` archive whose entry name contains `../` (or an absolute path) can therefore cause files to be written outside the output directory chosen by the user. This is a "zip-slip" / directory-traversal arbitrary file write (CWE-22).

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/uncbv
Introduced in: 0.0.0-0Fixed in: 0.3.1

Upgrade uncbv to 0.3.1 or newer (ecosystem crates.io).

References