CVE-2024-0406
published 2024-04-06CVE-2024-0406: A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.93%
56.5th percentile
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mholt_archiver | 0 – 3.5.1 | — |
| github.com | mholt_archiver | 3.0.0 – 3.5.1 | — |
| github.com | mholt_archiver_v3 | 0 – 3.5.1 | — |
| github.com | mholt_archiver_v3 | 3.0.0 – 3.5.1 | — |
| github.com | mholt_archiver_v3_github.com_mholt_archiver_v3 | v3.0.0 – v3.5.1 | — |
| mholt | archiver | >= 3.0.0 < 4.0.0 | 4.0.0 |
| redhat | advanced_cluster_security | — | — |
| redhat | openshift_container_platform | >= 4.18 < 4.18.4 | 4.18.4 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
ghsa7.8HIGH
osv7.8HIGH
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
osv·2025-04-14·CVSS 7.8
CVE-2025-3445 [HIGH] mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library.
When using the archiver.Unarchive functionality with ZIP files, like this: archiver.Unarchive(zipFile, outputDir), A crafted ZIP file can be extracted in such a way that it writes files to the affected system with the same privileges as the application executing this vulnerable functionality. Consequently, sensitive files may be overwritten, potentially leading to privilege escalation, code execution, and other severe outcomes in some cases.
It's worth noting t
GHSA
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
ghsa·2025-04-14·CVSS 7.8
CVE-2025-3445 [HIGH] CWE-22 mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
mholt/archiver Vulnerable to Path Traversal via Crafted ZIP File
A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library.
When using the archiver.Unarchive functionality with ZIP files, like this: archiver.Unarchive(zipFile, outputDir), A crafted ZIP file can be extracted in such a way that it writes files to the affected system with the same privileges as the application executing this vulnerable functionality. Consequently, sensitive files may be overwritten, potentially leading to privilege escalation, code execution, and other severe outcomes in some cases.
It's worth noting t
OSV
Archiver Path Traversal vulnerability in github.com/mholt/archiver
osv·2024-06-05
CVE-2024-0406 Archiver Path Traversal vulnerability in github.com/mholt/archiver
Archiver Path Traversal vulnerability in github.com/mholt/archiver
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
OSV
Archiver Path Traversal vulnerability
osv·2024-04-06
CVE-2024-0406 [MEDIUM] Archiver Path Traversal vulnerability
Archiver Path Traversal vulnerability
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
GHSA
Archiver Path Traversal vulnerability
ghsa·2024-04-06
CVE-2024-0406 [MEDIUM] CWE-22 Archiver Path Traversal vulnerability
Archiver Path Traversal vulnerability
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Red Hat
mholt/archiver: A Path Traversal "Zip Slip" vulnerability in mholt/archiver
vendor_redhat·2025-04-13·CVSS 6.1
CVE-2025-3445 [MEDIUM] CWE-22 mholt/archiver: A Path Traversal "Zip Slip" vulnerability in mholt/archiver
mholt/archiver: A Path Traversal "Zip Slip" vulnerability in mholt/archiver
A Path Traversal "Zip Slip" vulnerability has been identified in mholt/archiver in Go. This vulnerability allows using a crafted ZIP file containing path traversal symlinks to create or overwrite files with the user's privileges or application utilizing the library.
When using the archiver.Unarchive functionality with ZIP files, like this: archiver.Unarchive(zipFile, outputDir), A crafted ZIP file can be extracted in such a way that it writes files to the affected system with the same privileges as the application executing this vulnerable functionality. Consequently, sensitive files may be overwritten, potentially leading to privilege escalation, code execution, and other severe outcomes in some cases.
It's worth
Red Hat
mholt/archiver: path traversal vulnerability
vendor_redhat·2024-01-31·CVSS 6.1
CVE-2024-0406 [MEDIUM] CWE-22 mholt/archiver: path traversal vulnerability
mholt/archiver: path traversal vulnerability
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
A flaw was discovered in the mholt/archiver package. This flaw allows an attacker to create a specially crafted tar file, which, when unpacked, may allow access to restricted files or directories. This issue can allow the creation or overwriting of files with the user's or application's privileges using the library.
Statement: This is a path traversal vulnerability in v3 of mhol/archiver and has been marked as moderate for a varie
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-04-06
Published