CVE-2025-55474: Zip Archive Unvalidated Pathinfo

Extracting path information from a ZipArchive entry using pathinfo() or dirname() without checking for directory traversal sequences ('..') can lead to Path Traversal or Zip Slip vulnerabilities if the extracted directories are used for local storage or file mappings. Discard ZIP entries that contain traversal sequences securely before utilizing directory st

Provally CuratedPublic repositoryMediumMedium confidenceVerifiedApache-2.0PHPβ
greprules fetch cve-2025-55474-zip-archive-unvalidated-pathinfo --engine opengrep

Description

Extracting path information from a ZipArchive entry using pathinfo() or dirname() without checking for directory traversal sequences ('..') can lead to Path Traversal or Zip Slip vulnerabilities if the extracted directories are used for local storage or file mappings. Discard ZIP entries that contain traversal sequences securely before utilizing directory st