A high-severity directory traversal flaw, CVE-2026-17524, has been disclosed in the zip-lib package before version 1.1.0, allowing attackers to bypass extraction safeguards and write files outside the intended destination folder. The bug stems from cached path-validation results during archive extraction: zip-lib checks the isOutsideTargetFolder condition only when an initial directory symlink is created, enabling later archive entries to evade traversal protections. The issue is mapped to CWE-22 and carries a CVSS 3.1 score reflecting network-exploitable impact with high confidentiality risk.
The vulnerability fits the long-running Zip Slip class of archive extraction bugs, in which crafted archive entries such as ../../ paths can overwrite arbitrary files and potentially lead to remote code execution across ZIP, TAR, JAR, CPIO, and other formats. Security research has shown this pattern affects thousands of projects across multiple ecosystems when extraction logic concatenates archive entry names without robust validation, and offensive testing tools such as Archive Pwn have made it easier to generate malicious archives using traversal paths, symlink abuse, Unicode tricks, and other bypass techniques. The zip-lib disclosure underscores that archive handling remains a persistent software supply chain and application security risk even years after the original Zip Slip wave of fixes.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Snyk newly received CVE-2026-17524 for a directory traversal vulnerability in zip-lib versions before 1.1.0. The flaw stems from cached path validation during extraction that can let attackers bypass protections against writing outside the target folder.
Pentagrid released Archive Pwn, a Python-based tool for generating malicious archive files to test for path traversal and related archive extraction vulnerabilities. The tool supports multiple archive formats and attack techniques including traversal, symlink abuse, Unicode normalization issues, and denial-of-service patterns.
Snyk publicly disclosed Zip Slip, a widespread archive extraction flaw that can enable arbitrary file overwrite and potentially remote code execution via directory traversal paths in crafted archives. The disclosure reported impact across thousands of projects and multiple ecosystems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcepentagrid.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.