Vulnerability intelligence
CVE-2018-1002208
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
CVSS Score
—
Unrated
EPSS — Exploit Probability
8.9%
Riskier than 95% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
Patch available
Vendor fix published
2 articles across 1 outlet · first covered Apr 30, 2026 · latest May 5, 2026
Coverage timeline
-
Hitachi Energy PCM600www.cisa.gov · May 5, 2026
-
ABB PCM600www.cisa.gov · Apr 30, 2026