CVE-2026-17524

Source
https://cve.org/CVERecord?id=CVE-2026-17524
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17524.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17524
Published
2026-07-28T05:00:00.713Z
Modified
2026-08-01T03:33:08.683874873Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
[none]
Details

Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction.

Database specific
{
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17524.json",
    "cna_assigner": "snyk"
}
References

Affected packages

Git / github.com/fpsqdb/zip-lib

Affected ranges

Type
GIT
Repo
https://github.com/fpsqdb/zip-lib
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.1.0"
        }
    ]
}

Affected versions

0.*
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.4.0
0.4.1
0.4.2
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
1.*
1.0.1
1.0.2
1.0.3
1.0.4
1.0.5
v0.*
v0.7.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17524.json"