Zip path traversal is a file extraction flaw where archive entries contain paths such as ../ that escape the intended destination directory. Instead of unpacking files safely, the application writes them to arbitrary locations on the host. In web applications, that can enable overwrite, persistence, or server-side code execution.
What Zip Path Traversal Means
Zip path traversal is a file extraction flaw, not just a bad filename. The attacker controls archive entry paths so the unpacker writes outside the intended destination, turning a routine extract operation into arbitrary file placement on the host.
How the Flaw Works During Extraction
The core mistake is trusting archive metadata as if it were a safe local path. Entries such as ../, absolute paths, drive prefixes, or encoded path tricks can redirect writes if the extraction logic does not normalise and constrain the destination before writing each file.
This is especially dangerous when extraction happens in a privileged process, a shared application directory, or a location later loaded by the web server. A zip file can then become a vehicle for overwriting configuration, planting files, or influencing code paths that were never meant to be writable.
Why It Becomes a Security Problem
Zip path traversal can lead to integrity loss first, then persistence or execution depending on what gets overwritten. In web environments, the impact often depends on whether the attacker can target startup scripts, application templates, upload handlers, cron jobs, or other executable or interpreted files.
Defences need to treat archive extraction as an untrusted input problem. Normalising paths, rejecting traversal sequences, enforcing a fixed extraction root, and checking the final resolved destination are the practical controls that stop the flaw from becoming host-level write access.
Common Ways It Is Missed
Developers often validate the archive name but not each entry, or they inspect the raw string before decoding and path resolution. That leaves room for alternative separators, nested directories, symbolic-link interactions, and platform-specific path behaviour to defeat superficial checks.
Another common mistake is assuming that a “safe” upload feature stays safe once the file is handed to a library. If the library extracts paths automatically, the security boundary moves into the unpacker, and the application still owns the risk.
Risk and Threat Considerations
Zip path traversal is dangerous because it can convert a file upload or import feature into a write primitive on the server. The risk is highest when the extracted location influences application execution, deployed content, or other sensitive files that the attacker can overwrite.
Failure mechanism: The extractor fails to constrain each archive entry to the intended directory after normalisation and resolution, so attacker-supplied paths escape the sandbox.
Impact: The application may overwrite files, plant persistent content, alter configuration, or in some deployments reach server-side code execution.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP ASVS, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP ASVS | V5 — File Handling | Zip path traversal is a file handling flaw that escapes the intended write directory. |
| V15 — Secure Coding and Architecture | Safe extraction depends on architectural constraints that keep writes inside a trusted boundary. | |
| Recommendation — Validate archive entry paths and constrain extraction to a fixed, approved directory. Design extraction workflows so untrusted archives cannot influence executable or sensitive paths. | ||
| CIS Controls v8 | CIS-16 — Application Software Security | The issue is an application input and file-handling weakness that belongs in secure software controls. |
| Recommendation — Harden file upload and extraction code to prevent path traversal and arbitrary file writes. | ||
| NIST SP 800-53 Rev 5 | SI-10 — Information Input Validation | Archive entry paths are untrusted input that must be validated before file creation. |
| Recommendation — Validate and normalise archive paths before writing any extracted file. | ||
Practitioner Guidance
What to watch for: Review any feature that unpacks archives on behalf of the user, especially where the destination is web-accessible, shared, or writable by a process that also serves code. If the feature accepts nested archives, symbolic links, or platform-specific paths, the extraction logic needs stricter validation than a simple filename check.
Practitioner takeaway: Treat archive extraction as a controlled write operation, not a convenience function, and verify the resolved final path before any file is written.
Related resources from NHI Mgmt Group
- How should security teams validate whether a web application is exposed to a zip path traversal issue before attempting any exploit testing?
- Why does a zip path traversal flaw in a web application create remote code execution risk?
- Why do path traversal bugs create identity and secrets risk?
- What do security teams get wrong about path traversal in file upload handlers?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 29, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org