Skip to content

fix(maintenance): harden extract against directory traversal and absolute path attacks - #29

Merged
ashishsinghbora merged 1 commit into
mainfrom
fix/archive-extraction-security
Sep 24, 2026
Merged

ashishsinghbora merged 1 commit into
mainfrom
fix/archive-extraction-security

Conversation

@ashishsinghbora

Copy link
Copy Markdown
Owner

Summary

  • Added security inspection of archive member paths prior to extraction to prevent Zip Slip and tar path traversal (../) or absolute path extraction (/etc/...).
  • Added checks for missing extractor binaries (tar, unzip, unrar, 7z/7za) with clear error messaging.
  • Added -l / --list option to inspect archive contents safely without extraction.
  • Added plain .tar format support.
  • Fully compatible with --help flag.

Verification

  • Tested normal archive extraction on .tar.gz and .zip.
  • Tested crafted archives containing ../evil.txt (path traversal) and /evil.txt (absolute path) — verified extraction is strictly blocked and exits non-zero.
  • Verified ShellCheck passes without warnings.
  • Verified test suite passes.

@ashishsinghbora ashishsinghbora left a comment

Copy link
Copy Markdown
Owner Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code review: confirmed zip slip and tar path traversal checks block malicious ../ and absolute paths, verified tool dependencies are checked before execution, and tested archive extraction.

@ashishsinghbora
ashishsinghbora merged commit acf5609 into main Sep 24, 2026
1 check passed
@ashishsinghbora
ashishsinghbora deleted the fix/archive-extraction-security branch September 24, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant