Join our Newsletter — 33% off our NHI Course

Zip Path Traversal

Zip path traversal is a file extraction flaw where archive entries contain paths such as ../ that escape the intended destination directory. Instead of unpacking files safely, the application writes them to arbitrary locations on the host. In web applications, that can enable overwrite, persistence, or server-side code execution.

What Zip Path Traversal Means

Zip path traversal is a file extraction flaw, not just a bad filename. The attacker controls archive entry paths so the unpacker writes outside the intended destination, turning a routine extract operation into arbitrary file placement on the host.

How the Flaw Works During Extraction

The core mistake is trusting archive metadata as if it were a safe local path. Entries such as ../, absolute paths, drive prefixes, or encoded path tricks can redirect writes if the extraction logic does not normalise and constrain the destination before writing each file.

This is especially dangerous when extraction happens in a privileged process, a shared application directory, or a location later loaded by the web server. A zip file can then become a vehicle for overwriting configuration, planting files, or influencing code paths that were never meant to be writable.

Why It Becomes a Security Problem

Zip path traversal can lead to integrity loss first, then persistence or execution depending on what gets overwritten. In web environments, the impact often depends on whether the attacker can target startup scripts, application templates, upload handlers, cron jobs, or other executable or interpreted files.

Defences need to treat archive extraction as an untrusted input problem. Normalising paths, rejecting traversal sequences, enforcing a fixed extraction root, and checking the final resolved destination are the practical controls that stop the flaw from becoming host-level write access.

Common Ways It Is Missed

Developers often validate the archive name but not each entry, or they inspect the raw string before decoding and path resolution. That leaves room for alternative separators, nested directories, symbolic-link interactions, and platform-specific path behaviour to defeat superficial checks.

Another common mistake is assuming that a “safe” upload feature stays safe once the file is handed to a library. If the library extracts paths automatically, the security boundary moves into the unpacker, and the application still owns the risk.

Risk and Threat Considerations

Zip path traversal is dangerous because it can convert a file upload or import feature into a write primitive on the server. The risk is highest when the extracted location influences application execution, deployed content, or other sensitive files that the attacker can overwrite.

Failure mechanism: The extractor fails to constrain each archive entry to the intended directory after normalisation and resolution, so attacker-supplied paths escape the sandbox.

Impact: The application may overwrite files, plant persistent content, alter configuration, or in some deployments reach server-side code execution.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
OWASP ASVS V5 — File Handling Zip path traversal is a file handling flaw that escapes the intended write directory.
V15 — Secure Coding and Architecture Safe extraction depends on architectural constraints that keep writes inside a trusted boundary.
Recommendation — Validate archive entry paths and constrain extraction to a fixed, approved directory. Design extraction workflows so untrusted archives cannot influence executable or sensitive paths.
CIS Controls v8 CIS-16 — Application Software Security The issue is an application input and file-handling weakness that belongs in secure software controls.
Recommendation — Harden file upload and extraction code to prevent path traversal and arbitrary file writes.
NIST SP 800-53 Rev 5 SI-10 — Information Input Validation Archive entry paths are untrusted input that must be validated before file creation.
Recommendation — Validate and normalise archive paths before writing any extracted file.

Practitioner Guidance

What to watch for: Review any feature that unpacks archives on behalf of the user, especially where the destination is web-accessible, shared, or writable by a process that also serves code. If the feature accepts nested archives, symbolic links, or platform-specific paths, the extraction logic needs stricter validation than a simple filename check.

Practitioner takeaway: Treat archive extraction as a controlled write operation, not a convenience function, and verify the resolved final path before any file is written.