Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-323p-5qr7-q36j

Опубликовано: 12 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1

Описание

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.

EPSS

Процентиль: 28%
0.00347
Низкий

7.1 High

CVSS4

Дефекты

CWE-22

Связанные уязвимости

nvd
9 дней назад

An interface that accepts file uploads from authenticated users extracts the contents of uploaded archives without validating that extracted file paths remain within the intended destination directory. This allows an authenticated attacker to craft an archive whose entries traverse outside the destination directory, causing the extraction process to write files to arbitrary locations with the privileges of that process. This could allow an attacker to inject fabricated records into the system's stored data or tamper with application configuration.

EPSS

Процентиль: 28%
0.00347
Низкий

7.1 High

CVSS4

Дефекты

CWE-22