CVE-2025-62156: Zip Slip Path Traversal Go

Constructing paths via `filepath.Join()` from an archive entry (e.g., `header.Name`) without checking if the resulting path is still within the destination directory leaves the application vulnerable to Zip Slip or Path Traversal attacks. Ensure you validate the path using `strings.HasPrefix(target, dest)`.

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Go
greprules fetch cve-2025-62156-zip-slip-path-traversal-go --engine opengrep

Description

Constructing paths via `filepath.Join()` from an archive entry (e.g., `header.Name`) without checking if the resulting path is still within the destination directory leaves the application vulnerable to Zip Slip or Path Traversal attacks. Ensure you validate the path using `strings.HasPrefix(target, dest)`.