CVE-2020-36560: Go-Unzip Project Go-Unzip

Critical severity, CVSS 9.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

Affected products

Published 2022-12-27. Last modified 2026-06-17.