Intel

AIKIDO-2025-10431

github.com/cilium/cilium-cli is vulnerable to Zip Slip

Zip Slip Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

75

High Risk

This Affects:

GOgithub.com/cilium/cilium-cli
0.18.0 - 0.18.4
Fixed in 0.18.5

TL;DR

Affected versions of this package are vulnerable to a directory traversal (zip slip) vulnerability in the extractZip function due to insufficient sanitization of file paths within ZIP archives. Malicious archive entries containing ../ or absolute paths may cause files to be extracted outside the intended destination directory, potentially overwriting arbitrary files on the file system.

Who does this affect?

You are affected if you are use a vulnerable version of github.com/cilium/cilium-cli.

Background info

github.com/cilium/cilium-cli is vulnerable to Zip Slip in versions 0.18.0 - 0.18.4.

How to fix this

Upgrade github.com/cilium/cilium-cli to the patch version.