CVE-2020-23171: Nim-Lang

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability in all versions of Nim-lang allows unauthenticated attackers to write files to arbitrary directories via a crafted zip file with dot-slash characters included in the name of the crafted file.

Affected products

Published 2021-08-10. Last modified 2026-06-17.