{"id":"CVE-2026-30973","aliases":["GHSA-rfx7-4xw3-gh4m"],"url":"https://o3.security/vulnerability/CVE-2026-30973","summary":"Zip Slip arbitrary file write in @appium/support ZIP extraction","details":"Appium is an automation framework that provides WebDriver-based automation possibilities for a wide range platforms. Prior to 7.0.6, @appium/support contains a ZIP extraction implementation (extractAllTo() via ZipExtractor.extract()) with a path traversal (Zip Slip) check that is non-functional. The check at line 88 of packages/support/lib/zip.js creates an Error object but never throws it, allowing malicious ZIP entries with ../ path components to write files outside the intended destination directory. This affects all JS-based extractions (the default code path), not only those using the fileNamesEncoding option. This vulnerability is fixed in 7.0.6.","published":"2026-03-10T17:33:41.009Z","modified":"2026-08-07T11:31:30.467284890Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@appium/support","fixedVersion":"7.0.6"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/appium/appium/releases/tag/@appium/support@7.0.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/30xxx/CVE-2026-30973.json"},{"type":"ADVISORY","url":"https://github.com/appium/appium/security/advisories/GHSA-rfx7-4xw3-gh4m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30973"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:30.467284890Z"}}