A AegiFlow
HIGHCVSS 7.7EPSS 0.3%

CVE-2026-50567

Fission: Zip Slip in pkg/utils/zip.go:Unarchive allows fetcher to write outside the destination directory

Published
2026-07-28
Modified
2026-07-28
EPSS percentile
22%
Aliases
GHSA-q6vm-xqc9-v3ff
Sources
github-advisory

Summary

`Unarchive` in `pkg/utils/zip.go` joined each archive entry name with the destination directory via `filepath.Join` and wrote the result without checking whether the resolved path stayed under the destination. A zip entry named `../../tmp/evil` therefore landed at `/tmp/evil`. An attacker who could control a `Package.Spec.Source.URL` or `Deployment.URL` archive could induce the fetcher (running as the per-environment pod's `fission-fetcher` sidecar) to write files anywhere that process could reach: into other tenants' `/packages/ /` directories, into mounted secret/config volumes, or into the fetcher's own binary. ### Affected - Project: `github.com/fission/fission` - Versions: all up to and including v1.24.0 - Audited commit: `647c141` - Component: `pkg/utils/zip.go` (`Unarchive`) - Configuration: default; triggered when the fetcher downloads and extracts a zip archive Fix section (paste into the Fix / Patches field) Fixed in [v1.25.0](https://github.com/fission/fission/releases/tag/v1.25.0) by: - [PR #3444](https://github.com/fission/fission/pull/3444) (commit [`55704aca`](https://github.com/fission/fission/commit/55704aca1b8d6f45bc7c7c2e4805c7e14875ec0f)) — `Unarchive` now opens an `os.Root` on the destination, validates each archive entry name (rejects absolute paths and `..` traversal), and refuses symlink entries up front. The `os.Root` confines every `mkdir` / `create` to the destination in the kernel. Regression coverage: `TestUnarchiveZipSlip` in `pkg/utils/zip_test.go` exercises parent-traversal, absolute-path, and symlink entries.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/fission/fission1.25.0

Remediation: Upgrade to 1.25.0 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.