CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-q6vm-xqc9-v3ff: Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

highCVSS 7.7CVE-2026-50567
Unarchive in pkg/utils/zip.go joined each archive entry name with the destination directory via filepath.Join and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named ../../tmp/evil therefore landed at /tmp/evil. An attacker who could control a Package.Spec.Source.URL or Deployment.URL archive could induce the fetcher (running as the per-environment pod's fission-fetcher sidecar) to write files anywhere that process could reach: into other tenants' /packages/<ns>/ directories, into mounted secret/config volumes, or into the fetcher's own binary. Affected - Project: github.com/fission/fission - Versions: all up to and including v1.24.0 - Audited commit: 647c141 - Component: pkg/utils/zip.go (Unarchive) - Configuration: default; triggered when the fetcher downloads and extracts a zip archive Fix section (paste into the Fix / Patches field) Fixed in v1.25.0 by: - PR #3444 (commit 55704aca) — Unarchive now opens an os.Root on the destination, validates each archive entry name (rejects absolute paths and .. traversal), and refuses symlink entries up front. The os.Root confines every mkdir / create to the destination in the kernel. Regression coverage: TestUnarchiveZipSlip in pkg/utils/zip_test.go exercises parent-traversal, absolute-path, and symlink entries.

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.7
Published
2026-07-28
Last updated
2026-07-28
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-q6vm-xqc9-v3ff

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-50567coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories