


Perceptive Security
SOC/SIEM Consultancy

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. …
Published:
28 juli 2026 om 00:00:00
Alert date:
28 juli 2026 om 09:00:52
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
Versions of the npm package zip-lib before 1.1.0 are vulnerable to a Directory Traversal attack exploiting a flaw in the caching mechanism used for path validation during ZIP extraction. The security function isOutsideTargetFolder only validates and caches a path when a directory symlink is first created, allowing an attacker to bypass subsequent checks. By manipulating symlinks during extraction, an attacker can write files outside the intended target directory. The vulnerability is tracked as CVE-2026-17524 and also identified by Snyk as SNYK-JS-ZIPLIB-13834403. A fix was introduced in version 1.1.0 of zip-lib. The issue was reported via GitHub and patched in a documented commit. Users of zip-lib are strongly advised to upgrade to version 1.1.0 or later to remediate this risk.
Technical details
Mitigation steps:
Affected products:
zip-lib < 1.1.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-17524
https://github.com/fpsqdb/zip-lib/commit/0c29b1e17050f2611f4f37e6aaa92a60b3cb89d5
https://github.com/fpsqdb/zip-lib/issues/14
https://security.snyk.io/vuln/SNYK-JS-ZIPLIB-13834403
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
