A vulnerability was found in zip-lib up to 1.0.x and classified as critical. The impacted element is the function isOutsideTargetFolder of the component Caching Mechanism For Path Validation. Such manipulation leads to path traversal.

This vulnerability is documented as CVE-2026-17524. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.