path-traversal

Warn

Audited by Socket on May 12, 2026

1 alert found:

Security
SecurityMEDIUM
references/poc-skeleton.md

This fragment is a clearly exploit-focused PoC skeleton for path traversal and unsafe archive extraction path manipulation (Zip Slip/Tar Slip with symlinks and a backslash normalization bypass). While it does not itself implement a malicious package function (pkg is a placeholder and extraction is not performed here), it generates weaponized archive artifacts and shows direct traversal payloads that would enable out-of-bound file reads/writes if used against a vulnerable dependency. Treat the pattern as high-risk for systems that extract untrusted archives or read files from user-controlled paths without strict normalization, confinement, and symlink-safe extraction safeguards.

Confidence: 86%Severity: 82%
Audit Metadata
Analyzed At
May 12, 2026, 05:09 PM
Package URL
pkg:socket/skills-sh/ByamB4%2Ffind-cve-agent%2Fpath-traversal%2F@2d9493fddf27de655f9efbed2485b4a5bdf3e1d6
Security Audit — socket — path-traversal