{"id":"CVE-2022-35410","aliases":["GHSA-f33p-9287-h552","PYSEC-2022-223"],"url":"https://o3.security/vulnerability/CVE-2022-35410","summary":"mat2 before 0.13.0 allows directory traversal during the ZIP archive cleaning process.","details":"mat2 (aka metadata anonymisation toolkit) before 0.13.0 allows ../ directory traversal during the ZIP archive cleaning process. This primarily affects mat2 web instances, in which clients could obtain sensitive information via a crafted archive.","published":"2022-07-08T18:15:10.103Z","modified":"2026-04-02T08:04:16.965823Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.02163,"percentile":0.81351,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"PyPI","name":"mat2","fixedVersion":"0.13.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://www.debian.org/security/2022/dsa-5185"},{"type":"REPORT","url":"https://0xacab.org/jvoisin/mat2/-/issues/174"},{"type":"FIX","url":"https://0xacab.org/jvoisin/mat2/-/commit/beebca4bf1cd3b935824c966ce077e7bcf610385"},{"type":"FIX","url":"https://dustri.org/b/mat2-0130.html"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35410"},{"type":"PACKAGE","url":"https://0xacab.org/jvoisin/mat2"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-f33p-9287-h552"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/mat2/PYSEC-2022-223.yaml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-04-02T08:04:16.965823Z"}}