THREAT OPS › Threat News › [GHSA] GHSA-f63g-88cj-hjf9 (high) — IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
[GHSA] GHSA-f63g-88cj-hjf9 (high) — IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
GHSA-f63g-88cj-hjf9 Severity: high CVE: CVE-2026-54550
IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries
### Summary
IzPack's `UnpackerBase.unpack()` resolves pack-file target paths without any canonical-path or directory-containment check. An attacker who distributes a trojanized installer JAR (the format is unsign
Indicators of compromise
- CVE-2026-54550cve
- java.iodomain
Original source: https://github.com/advisories/GHSA-f63g-88cj-hjf9