top of page
perceptive_background_267k.jpg

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. …

Published:

28 juli 2026 om 00:00:00

Alert date:

28 juli 2026 om 09:00:52

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Web Technologies

Versions of the npm package zip-lib before 1.1.0 are vulnerable to a Directory Traversal attack exploiting a flaw in the caching mechanism used for path validation during ZIP extraction. The security function isOutsideTargetFolder only validates and caches a path when a directory symlink is first created, allowing an attacker to bypass subsequent checks. By manipulating symlinks during extraction, an attacker can write files outside the intended target directory. The vulnerability is tracked as CVE-2026-17524 and also identified by Snyk as SNYK-JS-ZIPLIB-13834403. A fix was introduced in version 1.1.0 of zip-lib. The issue was reported via GitHub and patched in a documented commit. Users of zip-lib are strongly advised to upgrade to version 1.1.0 or later to remediate this risk.

Technical details

Mitigation steps:

Affected products:

zip-lib < 1.1.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page