top of page
perceptive_background_267k.jpg

IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack…

Published:

26 augustus 2026 om 00:00:00

Alert date:

26 augustus 2026 om 18:17:38

Source:

nvd.nist.gov

Click to open the original link from this advisory

Supply Chain & Dependencies, Enterprise Applications

IzPack versions 5.2.6 and earlier contain a path traversal vulnerability in the UnpackerBase.unpack() method. The vulnerability arises because attacker-controlled PackFile targetPath values are passed through IoHelper.translatePath(), which only converts path separators without normalizing parent-directory segments or enforcing destination containment. This allows a malicious installer pack entry containing ../ sequences to write files outside the intended installation directory. Exploitation could result in files being written to startup folders, executable search paths, or other sensitive locations accessible with the victim's privileges. The attack is triggered when a victim runs a maliciously crafted installer. Fixes have been committed to the IzPack GitHub repository and a security advisory has been published. Users are advised to update to a patched version as soon as available.

Technical details

Mitigation steps:

Affected products:

IzPack 5.2.6 and earlier

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page