{"id":"CVE-2018-1002205","aliases":["GHSA-7378-6268-4278"],"url":"https://o3.security/vulnerability/CVE-2018-1002205","summary":"DotNetZip Zip-Slip Vulnerability","details":"DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","published":"2018-07-25T17:29:01.813Z","modified":"2026-07-08T05:50:43.312798742Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"DotNetZip","fixedVersion":"1.11.0"}],"fix":{"url":"https://github.com/haf/DotNetZip.Semverd/commit/55d2c13c0cc64654e18fcdd0038fdb3d7458e366","label":"haf/DotNetZip.Semverd@55d2c13"},"references":[{"type":"ADVISORY","url":"https://github.com/snyk/zip-slip-vulnerability"},{"type":"ADVISORY","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-DOTNET-DOTNETZIP-60245"},{"type":"FIX","url":"https://github.com/haf/DotNetZip.Semverd/commit/55d2c13c0cc64654e18fcdd0038fdb3d7458e366"},{"type":"FIX","url":"https://github.com/haf/DotNetZip.Semverd/pull/121"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:50:43.312798742Z"}}