CVE-2026-44788
MEDIUMSharpCompress: Directory traversal via directory entries in WriteToDirectory (zip slip variant)
Title source: cnaDescription
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious archive to create directories outside the intended extraction root. For TAR archives, this can be escalated to arbitrary file writes by chaining with a symlink entry, giving a full write primitive on the target filesystem subject to the permissions of the running process.
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/adamhathcock/sharpcompress/security/advisories/GHSA-6c8g-7p36-r338
Scores
CVSS v3
5.9
EPSS
0.0029
EPSS Percentile
20.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
Status
published
Products (3)
adamhathcock/sharpcompress
< 0.47.4
adamhathcock/sharpcompress
<= 0.47.4
sharpcompress_project/sharpcompress
< 0.47.4
Published
May 26, 2026
Tracked Since
May 27, 2026