A zip traversal attack uses crafted archive paths to write files outside the intended extraction directory. This can overwrite sensitive app files or place content in locations where it may be executed or trusted, making safe archive extraction and path validation essential controls.
What a zip traversal attack is
A zip traversal attack abuses archive file paths, such as "../" segments or absolute paths, so extraction writes outside the intended folder. The vulnerability is in the extractor’s trust of archive metadata, not in compression itself.
This matters because the extracted content can escape the sandbox-like boundary an application expects. If the destination path is not normalized and checked, a crafted archive can target sensitive application files, configuration, or other writable locations on disk.
How path traversal succeeds during extraction
Most archive libraries preserve entry names unless the caller explicitly validates them. That means the extractor may join a base directory with a malicious entry path and resolve it to a different location than intended. The danger increases when the application extracts with elevated filesystem permissions or runs in a directory shared by multiple services.
Traversal is often effective because the archive format is treated as trusted input. A filename that looks harmless inside the archive can become dangerous once the filesystem normalises separators, resolves parent references, or follows symlinks.
Why zip traversal becomes a security issue
The primary security impact is arbitrary file write. That can overwrite application code, plant web-accessible content, replace startup scripts, or modify configuration files that affect authentication, logging, or later execution. In some environments, a write outside the extraction tree can become a stepping stone to code execution or persistent compromise.
The issue is especially serious when archives are uploaded by users, pulled from third parties, or handled by automation that assumes the contents are benign. A successful traversal can also break integrity guarantees for deployments, backups, and software update flows.
Safe handling and validation expectations
Defensive extraction should treat every archive entry as untrusted path data. Normalise each target path, reject absolute paths and parent-directory traversal, and confirm the final resolved destination still sits under the intended extraction root. Many safe implementations also block symlink tricks and enforce allowlists for file types or filenames.
Where archive handling is part of a larger workflow, the safest pattern is to extract into a disposable location with minimal permissions and then move only approved files into their final destination. That reduces the blast radius if a malicious archive slips through validation.
Risk and Threat Considerations
Zip traversal is dangerous because a single crafted archive can turn a file extraction step into an arbitrary write primitive. In practice, that can overwrite code, alter configuration, or place payloads where a service later loads or executes them.
Failure mechanism: The extractor trusts archive paths, resolves them unsafely, or fails to enforce a canonical destination directory, so path separators and parent references escape the intended boundary.
Impact: Attackers may achieve integrity loss, persistence, service disruption, or in some cases code execution, especially when extraction runs with privileged filesystem access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CIS Controls v8 and OWASP ASVS set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | SI-10 — Information Input Validation | Zip traversal is unsafe input that must be validated before extraction. |
| CM-5 — Access Restrictions for Change | Malicious extraction can change files and configurations beyond the expected scope. | |
| Recommendation — Validate archive entry paths before writing files outside the intended directory. Restrict write paths so extracted content cannot alter sensitive system locations. | ||
| CIS Controls v8 | CIS-8 — Audit Log Management | Archive extraction abuse is easier to detect when file-write activity is logged and reviewed. |
| Recommendation — Log extraction and file-write activity to spot unexpected paths and overwrite attempts. | ||
| ISO/IEC 27001:2022 | A.8.28 — Secure coding | Safe archive extraction is a secure-development control issue in application code. |
| Recommendation — Implement secure path normalization and rejection logic in archive-handling code. | ||
| OWASP ASVS | V5 — File Handling | Archive extraction is a file-handling security requirement that must prevent path traversal. |
| Recommendation — Verify uploaded archives cannot write outside the allowed extraction directory. | ||
Practitioner Guidance
What to watch for: Treat any archive ingestion path as a trust boundary. The key judgement is whether the code validates the resolved extraction target, not whether the filename merely looks reasonable in the archive listing.
Practitioner takeaway: The safest control is not “scan the zip later”, but “prove every extracted path stays inside the allowed directory before a single byte is written.”
Related resources from NHI Mgmt Group
- Why do unauthenticated file upload and path traversal flaws create such a large attack surface in enterprise web apps?
- What are the signs that path traversal and reflected XSS are being used together in an attack chain?
- How should security teams validate whether a web application is exposed to a zip path traversal issue before attempting any exploit testing?
- Why does a zip path traversal flaw in a web application create remote code execution risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org