WhisperX tag archive

#Zip Slip

This page collects WhisperX intelligence signals tagged #Zip Slip. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (3)

The Lab · 2026-04-06 16:27:24 · GitHub Issues

1. Wanaku CLI ZipHelper Exposed: Zip Slip Path Traversal Vulnerability Allows Arbitrary File Write

A critical path traversal vulnerability has been identified in the Wanaku CLI's ZipHelper component, exposing systems to Zip Slip attacks. The flaw allows a maliciously crafted zip file to write arbitrary files outside the intended extraction directory, potentially leading to system compromise, data overwrite, or remot...

The Lab · 2026-04-13 02:22:37 · GitHub Issues

2. Hermes CLI Path Traversal Vulnerability: Malicious Archives Could Overwrite System Files

A critical path traversal vulnerability in the Hermes CLI tool's profile archive extraction has been identified and patched. The flaw, a classic 'zip slip' attack vector, allowed a maliciously crafted `.tar.gz` archive to write files outside the intended destination directory. This created a direct risk where an attack...

The Lab · 2026-05-05 02:54:07 · GitHub Issues

3. CVE-2026-23949 Exposes jaraco-context to Critical Zip Slip Path Traversal — Version 6.0.1 at Risk

A high-severity Zip Slip path traversal vulnerability has been identified in jaraco-context 6.0.1, raising urgent concerns for developers and organizations that rely on the widely-used Python package. The flaw, tracked as CVE-2026-23949, resides in the `jaraco.context.tarball()` function and may allow attackers to extr...