Intel

AIKIDO-2025-10532

SharpZipLib is vulnerable to Path Traversal

Path TraversalCVE-2021-32840 Published Aug 6, 2025

73

High Risk

This Affects:

DOTNETSharpZipLib
0.0.1 - 1.3.2
Fixed in 1.3.3
Are you affected? Scan for Free

TL;DR

Several path traversal vulnerabilities were identified in SharpZipLib (CVE-2021-32840, CVE-2021-32841, CVE-2021-32842), which may allow attackers to write files to arbitrary locations on the file system during archive extraction. These flaws can be exploited to overwrite critical files or place malicious files in sensitive directories, potentially leading to arbitrary code execution.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

SharpZipLib is vulnerable to Path Traversal in versions 0.0.1 - 1.3.2.

How to fix this

Upgrade the SharpZipLib library to the patch version.