A bug bounty researcher chained an XML External Entity (XXE) flaw with a ZIP directory-traversal vulnerability in an unnamed Java web application that accepted a custom ZIP-based .xyz package. The application extracted uploaded archives and parsed an XML manifest, allowing a locally referenced external entity to expose /etc/hosts and support further directory enumeration.
After identifying an application JSP template, the researcher used the archive extraction flaw—commonly known as Zip Slip—to overwrite it with a web shell, achieving remote code execution once cached content expired. The case demonstrates how unsafe XML parser defaults and insufficient archive-path validation can turn file-upload functionality into server compromise; the organization reportedly remediated the findings within 12 hours.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The unnamed organization's security team reportedly fixed the chained XXE and ZIP directory-traversal vulnerabilities in less than 12 hours after they were reported.
The researcher used XXE directory enumeration to identify a JSP template, then exploited ZIP directory traversal during archive extraction to overwrite sitemap.jsp with a web shell. The shell became accessible after cached content expired, resulting in remote code execution on the application server.
A bug bounty researcher found that an unnamed Java web application accepted ZIP-based .xyz uploads and processed an XML manifest with XXE enabled. A local entity referencing file:///etc/hosts disclosed the server's hosts file in the application's confirmation page.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.