---
cve: "CVE-2018-1002207"
severity: "LOW"
cvss: 3.1
epss: "2.5%"
vendor: "golang"
kev: false
exploited: false
published: "2018-07-25 17:29:02"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-09T12:28:36+02:00"
---

# CVE-2018-1002207

> 3.1 LOW · 🧪 PoC

## Beschreibung

mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

## Patch verfügbar (OSV)

- e4ef56d48eb029648b0e895bb0b6a393ef0829c3 (Commit)

## Referenzen

- <https://snyk.io/research/zip-slip-vulnerability>
- <https://github.com/snyk/zip-slip-vulnerability>
- <https://github.com/mholt/archiver/pull/65>
- <https://github.com/mholt/archiver/commit/e4ef56d48eb029648b0e895bb0b6a393ef0829c3>
- <https://snyk.io/vuln/SNYK-GOLANG-GITHUBCOMMHOLTARCHIVERCMDARCHIVER-50071>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2018-1002207) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
