WhisperX tag archive

#zip-slip

This page collects WhisperX intelligence signals tagged #zip-slip. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (2)

The Lab · 2026-04-01 02:26:57 · GitHub Issues

1. P1 Vulnerability in XPN: Zip Extraction Exposes Path Traversal Risk

A critical security flaw in the XPN software's archive handling allows attackers to write files anywhere on a user's system. The vulnerability, a classic 'zip-slip' attack, resides in the `XOutshine.h` export module. The code directly passes user-supplied filenames from a `.xpn` archive to the extraction function witho...

The Lab · 2026-05-09 23:31:48 · GitHub Issues

2. Critical Zip-Slip Path Traversal Vulnerability in Plugin Installation Allows Arbitrary File Overwrite

A critical path traversal vulnerability has been disclosed in the plugin installation mechanism, where files are written to paths constructed from registry-supplied filenames without validating that destinations remain within the intended plugin directory. The flaw, classified as a zip-slip vulnerability, could allow a...