{"id":"CVE-2018-1002201","details":"zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","aliases":["GHSA-qcf3-9vmh-xw4r","SNYK-JAVA-ORGZEROTURNAROUND-31681"],"modified":"2026-07-09T00:22:00.868323Z","published":"2018-07-25T17:29:00.500Z","references":[{"type":"REPORT","url":"https://github.com/zeroturnaround/zt-zip/blob/zt-zip-1.13/Changelog.txt"},{"type":"FIX","url":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff"},{"type":"FIX","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGZEROTURNAROUND-31681"},{"type":"EVIDENCE","url":"https://github.com/snyk/zip-slip-vulnerability"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/zeroturnaround/zt-zip","events":[{"introduced":"0"},{"fixed":"2aa8c72a6b2a2cb14e8a5cd3891fbba4d6cbd905"},{"fixed":"759b72f33bc8f4d69f84f09fcb7f010ad45d6fff"}],"database_specific":{"cpe":"cpe:2.3:a:jrebel:zt-zip:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.13"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["zt-zip-1.12","zt-zip-1.11","zt-zip-1.10","zt-zip-1.9","zt-zip-1.8","zt-zip-1.7","zt-zip-1.6","zt-zip-1.5","zt-zip-1.4","zt-zip-1.3","zt-zip-1.2","zt-zip-1.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1002201.json","vanir_signatures_modified":"2026-07-09T00:22:00Z","vanir_signatures":[{"target":{"file":"src/main/java/org/zeroturnaround/zip/ZipUtil.java","function":"process"},"deprecated":false,"digest":{"length":731,"function_hash":"279750403654855414608833557685175274410"},"id":"CVE-2018-1002201-22c34fac","signature_type":"Function","signature_version":"v1","source":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff","target":{"file":"src/main/java/org/zeroturnaround/zip/ZipUtil.java","function":"process"},"deprecated":false,"digest":{"function_hash":"198455943215700953213808939616267215482","length":624},"id":"CVE-2018-1002201-9dc389e7"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff","target":{"file":"src/main/java/org/zeroturnaround/zip/ZipUtil.java"},"deprecated":false,"digest":{"line_hashes":["310601281774499144755135626491352513510","274360009946576874522182633462003745653","73907614146411361057697097564316388116","251291736049655420166330684889846297678","220410006497838349652649523892244530990","31749547053909711789217358615698290078","100437989808543317718932101059407095646","162595804253701327466380441767224941935","111021639111426693295759285248971701321","124685360062642808386369791959263542763","144328565222130707453886345860151779529","119303119309932656875971493311413567506","41540335934033229366450312583384951076","104845014972195126914457114245168811422","73907614146411361057697097564316388116","251291736049655420166330684889846297678"],"threshold":0.9},"id":"CVE-2018-1002201-d82e4601"},{"signature_version":"v1","source":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff","target":{"file":"src/main/java/org/zeroturnaround/zip/ZipUtil.java","function":"process"},"deprecated":false,"digest":{"function_hash":"86450819048780533944105473355824873319","length":604},"id":"CVE-2018-1002201-e8dac007","signature_type":"Function"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}