A directory traversal vulnerability exists in python-libarchive through version 4.2.1, specifically in the extract functionality implemented in zip.py for ZipFile.extractall and ZipFile.extract. This flaw allows attackers to craft ZIP archives containing files with path traversal sequences (such as '../'), resulting in arbitrary file creation outside the intended extraction directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for CVE-2024-55587, a vulnerability in the Python libarchive library's extractall method. The repository contains two Python scripts: 'generate_zip.py' creates a malicious ZIP file ('exploit.zip') that includes a file with an absolute path ('/tmp/vulnerable.txt'). 'vulnerable_unzip.py' demonstrates how a vulnerable application using libarchive's extractall method can be exploited to write files to arbitrary locations on the filesystem. The exploit demonstrates an arbitrary file write vulnerability, which could be leveraged for further attacks if an application extracts untrusted ZIP files using libarchive without proper validation. No network endpoints are involved; the attack vector is local file extraction. The repository structure is simple, with clear separation between the exploit generator and the vulnerable example.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.