path-traversal
Warn
Audited by Socket on May 12, 2026
1 alert found:
SecuritySecurityreferences/poc-skeleton.md
MEDIUMSecurityMEDIUM
references/poc-skeleton.md
This fragment is a clearly exploit-focused PoC skeleton for path traversal and unsafe archive extraction path manipulation (Zip Slip/Tar Slip with symlinks and a backslash normalization bypass). While it does not itself implement a malicious package function (pkg is a placeholder and extraction is not performed here), it generates weaponized archive artifacts and shows direct traversal payloads that would enable out-of-bound file reads/writes if used against a vulnerable dependency. Treat the pattern as high-risk for systems that extract untrusted archives or read files from user-controlled paths without strict normalization, confinement, and symlink-safe extraction safeguards.
Confidence: 86%Severity: 82%
Audit Metadata