CVE-2026-53486: Archive Linkname Path Traversal
Archive extraction vulnerable to path traversal (Zip Slip/symlink escape). The `linkname` property from the archive header is passed directly to file-system link creation APIs without verifying that the target path resolves within the intended extraction directory. An attacker can craft an archive with malicious links to overwrite or read sensitive files. En
greprules fetch cve-2026-53486-archive-linkname-path-traversal --engine opengrepDescription
Archive extraction vulnerable to path traversal (Zip Slip/symlink escape). The `linkname` property from the archive header is passed directly to file-system link creation APIs without verifying that the target path resolves within the intended extraction directory. An attacker can craft an archive with malicious links to overwrite or read sensitive files. En
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.