Archive Extraction Is a Filesystem Security Boundary
Archive Extraction Is a Filesystem Security Boundary An archive extractor can receive a destination directory, join each stored name beneath it, and still write somewhere else. The gap appears when archive metadata is treated as harmless naming information even though extraction ultimately asks a filesystem to resolve paths, links, and object types with its own semantics. The familiar ../ traversal is only the most visible form of the problem. Absolute paths, symbolic links, hard links, platform-specific path syntax, pre-existing filesystem objects, and replacement races can all affect where a write lands. A robust design therefore cannot reduce extraction safety to a string check performed once before files are created.