CVE-2026-44695: Archive Manifest Path Traversal

Constructing file paths by joining an untrusted property from an array/iterable (such as an archive manifest) can lead to Path Traversal vulnerabilities if the property contains characters like `../`. When these paths are passed to filesystem read operations, it results in arbitrary file read. Iterate and extract buffer streams securely instead of writing un

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-44695-archive-manifest-path-traversal --engine opengrep

Description

Constructing file paths by joining an untrusted property from an array/iterable (such as an archive manifest) can lead to Path Traversal vulnerabilities if the property contains characters like `../`. When these paths are passed to filesystem read operations, it results in arbitrary file read. Iterate and extract buffer streams securely instead of writing un