Join our Newsletter — 33% off our NHI Course
Home› Glossary› Threats, Abuse & Incident Response› Zip Path Traversal
Threats, Abuse & Incident Response

Zip Path Traversal

← Back to Glossary
By NHI Mgmt Group Updated September 29, 2026 Domain: Threats, Abuse & Incident Response

Zip path traversal is a file extraction flaw where archive entries contain paths such as ../ that escape the intended destination directory. Instead of unpacking files safely, the application writes them to arbitrary locations on the host. In web applications, that can enable overwrite, persistence, or server-side code execution.

What Zip Path Traversal Means

Zip path traversal is a file extraction flaw, not just a bad filename. The attacker controls archive entry paths so the unpacker writes outside the intended destination, turning a routine extract operation into arbitrary file placement on the host.

How the Flaw Works During Extraction

The core mistake is trusting archive metadata as if it were a safe local path. Entries such as ../, absolute paths, drive prefixes, or encoded path tricks can redirect writes if the extraction logic does not normalise and constrain the destination before writing each file.

This is especially dangerous when extraction happens in a privileged process, a shared application directory, or a location later loaded by the web server. A zip file can then become a vehicle for overwriting configuration, planting files, or influencing code paths that were never meant to be writable.

Why It Becomes a Security Problem

Zip path traversal can lead to integrity loss first, then persistence or execution depending on what gets overwritten. In web environments, the impact often depends on whether the attacker can target startup scripts, application templates, upload handlers, cron jobs, or other executable or interpreted files.

Defences need to treat archive extraction as an untrusted input problem. Normalising paths, rejecting traversal sequences, enforcing a fixed extraction root, and checking the final resolved destination are the practical controls that stop the flaw from becoming host-level write access.

Common Ways It Is Missed

Developers often validate the archive name but not each entry, or they inspect the raw string before decoding and path resolution. That leaves room for alternative separators, nested directories, symbolic-link interactions, and platform-specific path behaviour to defeat superficial checks.

Another common mistake is assuming that a “safe” upload feature stays safe once the file is handed to a library. If the library extracts paths automatically, the security boundary moves into the unpacker, and the application still owns the risk.

Risk and Threat Considerations

Zip path traversal is dangerous because it can convert a file upload or import feature into a write primitive on the server. The risk is highest when the extracted location influences application execution, deployed content, or other sensitive files that the attacker can overwrite.

Failure mechanism: The extractor fails to constrain each archive entry to the intended directory after normalisation and resolution, so attacker-supplied paths escape the sandbox.

Impact: The application may overwrite files, plant persistent content, alter configuration, or in some deployments reach server-side code execution.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV5 — File HandlingZip path traversal is a file handling flaw that escapes the intended write directory.
V15 — Secure Coding and ArchitectureSafe extraction depends on architectural constraints that keep writes inside a trusted boundary.
Recommendation — Validate archive entry paths and constrain extraction to a fixed, approved directory. Design extraction workflows so untrusted archives cannot influence executable or sensitive paths.
CIS Controls v8CIS-16 — Application Software SecurityThe issue is an application input and file-handling weakness that belongs in secure software controls.
Recommendation — Harden file upload and extraction code to prevent path traversal and arbitrary file writes.
NIST SP 800-53 Rev 5SI-10 — Information Input ValidationArchive entry paths are untrusted input that must be validated before file creation.
Recommendation — Validate and normalise archive paths before writing any extracted file.

Practitioner Guidance

What to watch for: Review any feature that unpacks archives on behalf of the user, especially where the destination is web-accessible, shared, or writable by a process that also serves code. If the feature accepts nested archives, symbolic links, or platform-specific paths, the extraction logic needs stricter validation than a simple filename check.

Practitioner takeaway: Treat archive extraction as a controlled write operation, not a convenience function, and verify the resolved final path before any file is written.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org