RustSec disclosed that unzip 0.1.0, a Rust crate for extracting ZIP archives, is vulnerable to Zip Slip path traversal in unzip::Unzipper::unzip. The function uses attacker-controlled archive entry names to construct output paths without rejecting traversal components or absolute paths, allowing a malicious ZIP file to write files outside the intended extraction directory and potentially enabling code execution. The issue is tracked as RUSTSEC-2026-0297 and maps to CWE-22, CWE-23, and CWE-36.
All published versions are affected: unzip has only one release, version 0.1.0, and no fix is available. RustSec also designated the crate unmaintained under RUSTSEC-2026-0296, noting that its known vulnerability will not be remediated; organizations using it should remove or replace the dependency with an actively maintained alternative such as the Rust zip crate and ensure ZIP extraction code validates destination paths.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
RustSec issued RUSTSEC-2026-0296 classifying `unzip` as unmaintained, stating its known Zip Slip issue will not be fixed. The advisory recommends migrating to an actively maintained alternative such as the `zip` crate.
RustSec issued RUSTSEC-2026-0297 for the path-traversal vulnerability affecting all published versions of `unzip`. No patched version is available; the flaw can enable arbitrary file writes and is categorized as code execution.
A directory-traversal (Zip Slip) flaw in `unzip::Unzipper::unzip` was reported. Attacker-controlled ZIP entry names containing traversal components or absolute paths can cause writes outside the selected extraction directory.
The Rust `unzip` crate released its only published version, 0.1.0, providing ZIP archive extraction functionality.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
rustsec.org
Open sourcerustsec.org
Open sourcecrates.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.