{"id":"RUSTSEC-2025-0168","summary":"Incorrect path canonicalization during Archive Extraction Leading to Arbitrary File Write","details":"In the archive extraction routine of affected versions of the zip crate, symbolic links earlier in the archive are allowed to be used for later files in the archive without validation of the final canonicalized path, allowing maliciously crafted archives to overwrite arbitrary files in the file system when extracted.\n\nFor more details, see the GitHub-hosted security advisory: \u003chttps://github.com/zip-rs/zip2/security/advisories/GHSA-94vh-gphv-8pm8\u003e","aliases":["CVE-2025-29787","GHSA-94vh-gphv-8pm8"],"modified":"2026-08-11T10:30:03.278476437Z","published":"2025-03-16T12:00:00Z","database_specific":{"license":"CC-BY-4.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/zip"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2025-0168.html"},{"type":"ADVISORY","url":"https://github.com/zip-rs/zip2/security/advisories/GHSA-94vh-gphv-8pm8"}],"affected":[{"package":{"name":"zip","ecosystem":"crates.io","purl":"pkg:cargo/zip"},"ranges":[{"type":"SEMVER","events":[{"introduced":"1.3.0"},{"fixed":"2.3.0"}]}],"ecosystem_specific":{"affected_functions":null,"affects":{"functions":["zip::read::ZipArchive::extract","zip::unstable::stream::ZipStreamReader::extract"],"arch":[],"os":[]}},"database_specific":{"cvss":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H","informational":null,"categories":[],"source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2025-0168.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:H/SI:H/SA:H"}]}