Utility for creating ZipSlip archives
-
Updated
Feb 9, 2023 - Python
Utility for creating ZipSlip archives
Utility script to test zip file upload functionality (and possible extraction of zip files) for vulnerabilities (aka Zip Slip)
A simple archiving and compression library for Java
Quick and Dirty POC for Zip Slip
Yara rules respository containing rules for exploits, malwares and cryptominers
Secure zip extraction for Rust & Python. Prevents Zip Slip, Zip Bombs, and symlink attacks.
Security-aware ZIP inspection for Python and CI: deterministic reports, policy checks, and safe extraction inspect before you extract.
Create and extract zip/tar archives with safe (zip-slip-proof) extraction by default. Pure Python, zero dependencies.
Professional TryHackMe walkthrough of The Hollow Shell, documenting web reconnaissance, source-code credential disclosure, Zip Slip, arbitrary file write, background-worker abuse, controlled code execution, and Linux post-exploitation.
Simulates an archive's entry list against the destination tree and refuses any plan whose containment depends on entry order
What an archive will do when you unpack it. A zip lists its contents twice and nothing makes the two agree; this reads both. No uploads, no lookups, no telemetry.
MCP server on the zipnative ZIP engine — 13 tools for AI agents: inspect, list and verify without extracting, extract with zip-slip / zip-bomb / symlink guards, create deterministic reproducible archives, modify without recompression. MCP 2026-07-28 + legacy, stdio & HTTP, sandboxed, no network path, ISO/IEC 21320-1 validated in CI. Node ≥22.
Catch path traversal in Go by checking that an untrusted path stays inside its root
CVE-2020-8254: Zip Slip in Pulse Secure VPN Windows Client
MAL-005: Zip Slip in Add Carbon Applications in WSO2 ESB
Agent-grade ZIP CLI on the zipnative engine — create deterministic, reproducible archives, list and inspect without extracting, extract with zip-slip / zip-bomb / symlink guards, verify, stream, modify without recompression. Stable --json contract for AI agents, ISO/IEC 21320-1 validated in CI. Node ≥22, zero extra dependencies.
WSO2-2021-1258: Zip Slip vulnerability in WSO2 ESB
A container-only teaching demo for path traversal (CWE-22 / Zip Slip): resolve-and-confine done right, with an opt-in vulnerable contrast. Educational code, local-only — not for deployment.
To associate your repository with the zip-slip topic, visit your repo's landing page and select "manage topics."