{"id":"CVE-2018-1002206","aliases":["GHSA-fxh6-w476-hgr4"],"url":"https://o3.security/vulnerability/CVE-2018-1002206","summary":"Directory Traversal in SharpCompress","details":"SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.","published":"2018-07-25T17:29:01.940Z","modified":"2026-07-08T14:13:57.689964Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":3,"affectedPackages":[{"ecosystem":"NuGet","name":"SharpCompress","fixedVersion":"0.21.0"}],"fix":{"url":"https://github.com/adamhathcock/sharpcompress/commit/42b1205fb435de523e6ef8ac5b7bafbe712997f6","label":"adamhathcock/sharpcompress@42b1205"},"references":[{"type":"FIX","url":"https://github.com/adamhathcock/sharpcompress/commit/42b1205fb435de523e6ef8ac5b7bafbe712997f6"},{"type":"FIX","url":"https://github.com/adamhathcock/sharpcompress/pull/374"},{"type":"EVIDENCE","url":"https://github.com/snyk/zip-slip-vulnerability"},{"type":"EVIDENCE","url":"https://snyk.io/research/zip-slip-vulnerability"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-DOTNET-SHARPCOMPRESS-60246"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:13:57.689964Z"}}