# std/zip.zig: perform backslash-to-forward-slash before isBadFilename\(\) · gitcafe/zig

[View on GitCafe](https://git.cafe/gitcafe/zig/commit/242102f9d113fff321559c8645e79a29f0bdf70d)

Repository: [gitcafe/zig](https://git.cafe/gitcafe/zig)

Visibility: public

Requested revision: 242102f9d113fff321559c8645e79a29f0bdf70d

Requested commit: 242102f9d113fff321559c8645e79a29f0bdf70d

Commit: 242102f9d113fff321559c8645e79a29f0bdf70d

Tree: 4c0e5787b20927009789740626d618d12b2bf809

Author: Frank Denis

Committer: Andrew Kelley

## Message

```
std/zip.zig: perform backslash-to-forward-slash before isBadFilename()

Previously, when extracting a ZIP file, isBadFilename(), which is
designed to reject ../ patterns to prevent directory traversal, was
called before normalizing backslashes to forward slashes.

This allowed path traversal sequences like ..\\..\\..\\etc\\passwd
which pass validation but are then converted to ../../../etc/passwd
for file extraction.

```

## Parents

- [6de23100352b9c94cc8c92737687091917951df3](https://git.cafe/gitcafe/zig/commit/6de23100352b9c94cc8c92737687091917951df3?format=markdown)

[Source at this commit](https://git.cafe/gitcafe/zig/tree/242102f9d113fff321559c8645e79a29f0bdf70d?format=markdown)
