GHSA-8x9r-hvwg-c55h
HIGHCVE-2026-35454A Zip Slip (CWE-22) vulnerability in coder/code-marketplace ≤ v2.4.1 allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names to a callback that wrote files via filepath.Join with no boundary check; filepath.Join resolved .. components but did not prevent the result from escaping the base path.
- Affected
- >=0, <1.2.3-0.20260402184705-988440dee05f, < 1.2.3-0.20260402184705-988440dee05f
- Fixed in
- 1.2.3-0.20260402184705-988440dee05f
- Weakness
- CWE-22
- Published
- 2026-04-04
- Source
- osv