DotNetZip Zip-Slip Vulnerability
Moderate severity
GitHub Reviewed
Published
Oct 16, 2018
to the GitHub Advisory Database
•
Updated May 6, 2025
Description
Published by the National Vulnerability Database
Jul 25, 2018
Published to the GitHub Advisory Database
Oct 16, 2018
Reviewed
Jun 16, 2020
Last updated
May 6, 2025
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
References