Utility for creating ZipSlip archives
-
Updated
Feb 9, 2023 - Python
Utility for creating ZipSlip archives
Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)
A simple archiving and compression library for Java
Quick and Dirty POC for Zip Slip
Yara rules respository containing rules for exploits, malwares and cryptominers
Secure zip extraction for Rust & Python. Prevents Zip Slip, Zip Bombs, and symlink attacks.
Security-aware ZIP inspection for Python and CI: deterministic reports, policy checks, and safe extraction inspect before you extract.
Simulates an archive's entry list against the destination tree and refuses any plan whose containment depends on entry order
Create and extract zip/tar archives with safe (zip-slip-proof) extraction by default. Pure Python, zero dependencies.
Detect unsafe tar/zip extractall() calls (CWE-22 tar-slip / zip-slip) and extract archives safely at runtime, with no dependencies.
What an archive will do when you unpack it. A zip lists its contents twice and nothing makes the two agree; this reads both. No uploads, no lookups, no telemetry.
MCP server on the zipnative ZIP engine — 13 tools for AI agents: inspect, list and verify without extracting, extract with zip-slip / zip-bomb / symlink guards, create deterministic reproducible archives, modify without recompression. MCP 2026-07-28 + legacy, stdio & HTTP, sandboxed, no network path, ISO/IEC 21320-1 validated in CI. Node ≥22.
Professional TryHackMe walkthrough of The Hollow Shell, documenting web reconnaissance, source-code credential disclosure, Zip Slip, arbitrary file write, background-worker abuse, controlled code execution, and Linux post-exploitation.
Agent-grade ZIP CLI on the zipnative engine — create deterministic, reproducible archives, list and inspect without extracting, extract with zip-slip / zip-bomb / symlink guards, verify, stream, modify without recompression. Stable --json contract for AI agents, ISO/IEC 21320-1 validated in CI. Node ≥22, zero extra dependencies.
CVE-2020-8254: Zip Slip in Pulse Secure VPN Windows Client
MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB
Catch path traversal in Go by checking that an untrusted path stays inside its root
DeepSeek Harness plugin
To associate your repository with the zip-slip topic, visit your repo's landing page and select "manage topics."