Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Fpsqdb
Fpsqdb zip-lib |
|
| Vendors & Products |
Fpsqdb
Fpsqdb zip-lib |
Tue, 28 Jul 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Versions of the package zip-lib before 1.1.0 are vulnerable to Directory Traversal via the caching mechanism for path validation during the extraction process. An attacker can bypass security checks designed to prevent directory traversal. The intended security function, isOutsideTargetFolder, only checks and caches the path status when the initial directory symlink is created during the first extraction. | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: snyk
Published:
Updated: 2026-07-28T16:06:25.209Z
Reserved: 2026-07-27T08:21:00.930Z
Link: CVE-2026-17524
Updated: 2026-07-28T16:06:21.304Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T20:27:01Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')