{"id":"CVE-2026-54550","aliases":["GHSA-f63g-88cj-hjf9"],"url":"https://o3.security/vulnerability/CVE-2026-54550","summary":"IzPack: Path Traversal in UnpackerBase allows writing files outside the installation directory via malicious pack entries","details":"IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without normalizing parent-directory segments or enforcing destination containment. A malicious installer pack entry containing ../ sequences can therefore write outside the intended installation directory to startup folders, executable search paths, or other locations accessible with the victim's privileges when the victim runs the installer.","published":"2026-08-26T14:24:06.879Z","modified":"2026-08-27T03:57:40.155746786Z","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N"},"epss":{"score":0.00377,"percentile":0.3054,"asOf":"2026-08-27"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.codehaus.izpack:izpack-installer","fixedVersion":null}],"fix":{"url":"https://github.com/izpack/izpack/commit/4233ba38d0f1825f9cf3e0204e5261a5498e29d8","label":"izpack/izpack@4233ba3"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54550.json"},{"type":"FIX","url":"https://github.com/izpack/izpack/commit/4233ba38d0f1825f9cf3e0204e5261a5498e29d8"},{"type":"FIX","url":"https://github.com/izpack/izpack/commit/8b7c6792c4fe85e3b1759c106aae39b904848466"},{"type":"FIX","url":"https://github.com/izpack/izpack/pull/1193"},{"type":"ADVISORY","url":"https://github.com/izpack/izpack/security/advisories/GHSA-f63g-88cj-hjf9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54550"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-27T03:57:40.155746786Z"}}