MyRobotLab / myrobotlab

Open Source Java Framework for Robotics and Creative Machine Control
Apache License 2.0
230 stars 108 forks source link

Extract files only within the destination directory #1428

Open rhckrtu opened 2 months ago

rhckrtu commented 2 months ago

Make sure files only get extracted within the specified destination to avoid the Zip Slip vulnerability. Without this patch the ZIP archive can contain relative paths and extract files to arbitrary paths the user has write permissions for.