THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f63g-88cj-hjf9 (high) — IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

[GHSA] GHSA-f63g-88cj-hjf9 (high) — IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

highgithub_advisoriesPublished 2026-08-26

GHSA-f63g-88cj-hjf9 Severity: high CVE: CVE-2026-54550

IzPack has Path Traversal in UnpackerBase that allows writing files outside the installation directory via malicious pack entries

### Summary

IzPack's `UnpackerBase.unpack()` resolves pack-file target paths without any canonical-path or directory-containment check. An attacker who distributes a trojanized installer JAR (the format is unsign

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f63g-88cj-hjf9