Zio
An abstract/virtual filesystem framework with many built-ins filesystems for .NET
Activity
- Latest release
- 2mo ago
- Total releases
- 48
- Cadence
- ~19 days
- Last 12 months
- 6
Reach
- Stars
- —
Details
- License
- BSD-2-Clause
- First release
- May 01, 2017
| Version | Released | |
|---|---|---|
0.24.0
minor
| ||
0.23.0
minor
| ||
0.22.2
patch
| ||
0.22.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.22.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.21.3
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.21.2
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.21.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.21.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.20.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.19.2
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.19.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.19.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.18.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.18.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.17.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.17.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.16.2
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.16.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.16.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.15.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.14.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.13.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.12.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.11.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.10.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.9.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.9.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.6
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.5
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.4
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.3
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.2
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.6.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.5.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.4.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.6
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.5
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.4
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.3
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.2
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.1
patch
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.3.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.2.0
minor
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev | ||
0.1.0
initial
1 CVE
GHSA-h39g-6x3c-7fq9
Apr 18, 2026
Zio has SubFileSystem Path Confinement Bypass via Unresolved `..` Segment
3.8
/ 10
Low
Local
Low
Low
None
Changed
Low
None
None
Summary
Affected Component
When the input ends with The resulting When this path reaches
The delegate filesystem receives Proof of Concept
ImpactThe escape is limited to directory level operations because appending a filename after Affected versions
0.1.0
0.10.0
0.11.0
0.12.0
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.17.1
+ 33 more Show less
0.18.0
0.18.1
0.19.0
0.19.1
0.19.2
0.2.0
0.20.0
0.21.0
0.21.1
0.21.2
0.21.3
0.22.0
0.22.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.3.5
0.3.6
0.4.0
0.5.0
0.6.0
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.8.0
0.9.0
0.9.1
Fixed in
0.22.2
References Updated Apr 18, 2026 · Source: OSV.dev |