High severity7.8NVD Advisory· Published Aug 30, 2023· Updated Jun 17, 2026
CVE-2023-39137
CVE-2023-39137
Description
An issue in Archive v3.3.7 allows attackers to spoof zip filenames which can lead to inconsistent filename parsing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
archivePub | < 3.3.8 | 3.3.8 |
Affected products
3- cpe:2.3:a:archive_project:archive:3.3.7:*:*:*:*:*:*:*
- Archive/Archivedescription
Patches
Vulnerability mechanics
References
8- blog.ostorlab.co/zip-packages-exploitation.htmlnvdExploitWEB
- ostorlab.co/vulndb/advisory/OVE-2023-3nvdExploitWEB
- github.com/advisories/GHSA-r285-q736-9v95ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-39137ghsaADVISORY
- www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_name_spoofing/nvdThird Party Advisory
- github.com/brendan-duncan/archive/commit/0d17b270a3c33d3bed56cadd9a43da7717ab11f4ghsaWEB
- github.com/brendan-duncan/archive/issues/266nvdIssue TrackingWEB
- www.rapid7.com/db/modules/exploit/windows/fileformat/winrar_name_spoofingghsaWEB
News mentions
0No linked articles in our index yet.