CVE-2026-47078
Received
Received - Intake
Relative Path Traversal in Erlang OTP zip Module
Vulnerability report for CVE-2026-47078, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-27
Last updated on: 2026-07-27
Assigner: EEF
Description
Description
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive.
zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a running integer counter: .. decrements it, normal path components increment it. The caller rejects only paths where the final counter value is less than zero. A path such as ../x/y causes the counter to go negative mid-traversal then recover to zero, passing validation while resolving to a location outside the extraction directory when joined with the current working directory via add_cwd.
This vulnerability is associated with program file lib/stdlib/src/zip.erl.
This issue affects OTP from OTP 27.1 before OTPΒ 29.0.4, OTPΒ 28.5.0.4 and OTPΒ 27.3.4.15, corresponding to stdlib from 6.1 before 8.0.3, 7.3.0.1 and 6.2.2.4.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| erlang | otp | to 29.0.4 (exc) |
| erlang | otp | 28.5.0.4 |
| erlang | otp | 27.3.4.15 |
| erlang | stdlib | to 8.0.3 (exc) |
| erlang | stdlib | 7.3.0.1 |
| erlang | stdlib | 6.2.2.4 |
| erlang | otp | From 27.1 (inc) to 29.0.4 (exc) |
| erlang | otp | to 8.0.3 (exc) |
| erlang | otp | to 7.3.0.1 (exc) |
| erlang | otp | to 6.2.2.4 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-23 | The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory. |