What is CVE-2026-17524?
CVE-2026-17524 is a Directory Traversal vulnerability in zip-lib versions before 1.1.0, exploiting the caching mechanism for path validation during extraction. It allows attackers to bypass the `isOutsideTargetFolder` security function and potentially write files outside the intended directory. Users should upgrade to version 1.1.0 or later immediately.
Azərbaycanca: CVE-2026-17524, zip-lib paketinin 1.1.0-dən əvvəlki versiyalarında çıxarış zamanı path validation-ın caching mexanizmi vasitəsilə Directory Traversal zəifliyidir. Bu zəiflik `isOutsideTargetFolder` funksiyasının təhlükəsizlik yoxlamalarını keçməyə imkan verərək, təcavüzkarın hədəf qovluqdan kənar fayllar yaratmasına səbəb ola bilər. İstifadəçilər dərhal 1.1.0 və ya daha yeni versiyaya yeniləməlidirlər.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of the zip-lib package are affected by CVE-2026-17524?
This vulnerability affects versions of the zip-lib package prior to 1.1.0.
How can users protect themselves against CVE-2026-17524?
Users should immediately upgrade the zip-lib package to version 1.1.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.