{"id":"GHSA-qcf3-9vmh-xw4r","summary":"Improper Limitation of a Pathname to a Restricted Directory in zt-zip","details":"zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","aliases":["CVE-2018-1002201","SNYK-JAVA-ORGZEROTURNAROUND-31681"],"modified":"2026-09-10T03:49:36.520555713Z","published":"2022-05-13T01:30:44Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-06-30T15:17:37Z","nvd_published_at":"2018-07-25T17:29:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1002201"},{"type":"WEB","url":"https://github.com/zeroturnaround/zt-zip/commit/759b72f33bc8f4d69f84f09fcb7f010ad45d6fff"},{"type":"WEB","url":"https://github.com/snyk/zip-slip-vulnerability"},{"type":"WEB","url":"https://github.com/zeroturnaround/zt-zip/blob/zt-zip-1.13/Changelog.txt"},{"type":"WEB","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGZEROTURNAROUND-31681"}],"affected":[{"package":{"name":"org.zeroturnaround:zt-zip","ecosystem":"Maven","purl":"pkg:maven/org.zeroturnaround/zt-zip"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13"}]}],"versions":["1.10","1.11","1.12","1.4","1.5","1.6","1.7","1.8","1.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qcf3-9vmh-xw4r/GHSA-qcf3-9vmh-xw4r.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"}]}