{"id":"GHSA-2rpm-4x8c-pvqg","summary":"Improper Limitation of a Pathname to a Restricted Directory in Zip4j","details":"zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","aliases":["CVE-2018-1002202"],"modified":"2026-03-16T03:10:18.240305Z","published":"2022-05-13T01:35:04Z","database_specific":{"nvd_published_at":"2018-07-25T17:29:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-06-30T14:43:07Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1002202"},{"type":"WEB","url":"https://github.com/snyk/zip-slip-vulnerability"},{"type":"WEB","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-NETLINGALAZIP4J-31679"},{"type":"WEB","url":"https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbmu03895en_us"}],"affected":[{"package":{"name":"net.lingala.zip4j:zip4j","ecosystem":"Maven","purl":"pkg:maven/net.lingala.zip4j/zip4j"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.3"}]}],"versions":["1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.1","1.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-2rpm-4x8c-pvqg/GHSA-2rpm-4x8c-pvqg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}