Showing 1 vulnerability on this page for Zio

Signals CISA KEV Ransomware Nuclei
NuGet vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment

# Summary `SubFileSystem` fails to confine operations to its declared sub path when the input path is `/../` (or equivalents `/../`, `/..\\`). This path passes all validation but resolves to the root of the parent filesystem, allowing directory level operations outside the intended boundary. # Affected Component `Zio.UPath.ValidateAndNormalize` `Zio.FileSystems.SubFileSystem` `UPath.ValidateAndNormalize` has a trailing slash optimisation. ```csharp if (!processParts && i + 1 == path.Length)

CWE-179CWE-22Apr 18, 2026
CVSS-v3.1EPSS-PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX