sevenz-rust
Activity
- Latest release
- 2y ago
- Total releases
- 29
- Cadence
- ~8 days
- Last 12 months
- 0
Details
- License
- Apache-2.0
- First release
- Aug 10, 2022
| Version | Released | |
|---|---|---|
0.6.1
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.6.1
unknown
Dependencies (16)
+ 8 more |
|
0.6.0
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.6.0
unknown
Dependencies (16)
+ 8 more |
|
0.5.4
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.5.4
unknown
Dependencies (16)
+ 8 more |
|
0.5.3
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.5.3
unknown
Dependencies (16)
+ 8 more |
|
0.5.2
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.5.2
unknown
Dependencies (16)
+ 8 more |
|
0.5.1
unknown
yanked
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.5.1
unknown
yanked
Dependencies (16)
+ 8 more |
|
0.5.0
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.5.0
unknown
Dependencies (16)
+ 8 more |
|
0.4.3
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.4.3
unknown
Dependencies (16)
+ 8 more |
|
0.4.2
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.4.2
unknown
Dependencies (16)
+ 8 more |
|
0.4.1
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.4.1
unknown
Dependencies (16)
+ 8 more |
|
0.4.0
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.4.0
unknown
Dependencies (16)
+ 8 more |
|
0.3.0
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.3.0
unknown
Dependencies (16)
+ 8 more |
|
0.2.11
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.11
unknown
Dependencies (14)
+ 6 more |
|
0.2.10
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.10
unknown
Dependencies (13)
+ 5 more |
|
0.2.9
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.9
unknown
Dependencies (13)
+ 5 more |
|
0.2.8
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.8
unknown
Dependencies (12)
+ 4 more |
|
0.2.7
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.7
unknown
Dependencies (12)
+ 4 more |
|
0.2.6
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.6
unknown
Dependencies (12)
+ 4 more |
|
0.2.5
unknown
yanked
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.5
unknown
yanked
Dependencies (12)
+ 4 more |
|
0.2.4
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.4
unknown
Dependencies (10)
+ 2 more |
|
0.2.3
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.3
unknown
Dependencies (10)
+ 2 more |
|
0.2.2
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.2
unknown
Dependencies (10)
+ 2 more |
|
0.2.0
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.2.0
unknown
Dependencies (9)
+ 1 more |
|
0.1.5
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.5
unknown
Dependencies (7)
|
|
0.1.4
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.4
unknown
Dependencies (4)
|
|
0.1.3
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.3
unknown
Dependencies (4)
|
|
0.1.2
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.2
unknown
Dependencies (4)
|
|
0.1.1
unknown
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.1
unknown
Dependencies (3)
|
|
0.1.0
unknown
yanked
2 CVEs
RUSTSEC-2026-0246
Aug 06, 2026
`sevenz-rust` is unmaintained The References Updated Aug 10, 2026 · Source: OSV.dev
RUSTSEC-2026-0245
Aug 06, 2026
Relative/Absolute Path Traversal (CWE-23/CWE-36) in `decompress_impl` that enables an arbitrary file write.
High
Local
Low
None
SummaryAll versions of This oversight allows a maliciously crafted archive to extract outside the extraction directory, from both relative paths such as DetailsThe following line numbers will be referencing the latest version v0.6.1. The specific point of failure is at
When the function iterates through each entry, it blindly joins the entry name with the output directory before passing the path into
StatusThe project has been abandoned and the repository has been deleted, so no upstream fix is expected. Users should migrate away from the library in favor of a modern up-to-date 7z library such as References Updated Aug 10, 2026 · Source: OSV.dev |
0.1.0
unknown
yanked
Dependencies (3)
|