{"id":"CVE-2026-54550","title":"IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers","summary":"IzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.j…","severity":"high","cvss":7.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N","cwe":["CWE-22"],"vendor":"codehaus","product":"org.codehaus.izpack:izpack-installer","affected":["org.codehaus.izpack:izpack-installer <= 5.2.6"],"published":"2026-08-26","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:09:13.080","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-54550","references":[{"url":"https://github.com/izpack/izpack/commit/4233ba38d0f1825f9cf3e0204e5261a5498e29d8","label":"security-advisories@github.com"},{"url":"https://github.com/izpack/izpack/commit/8b7c6792c4fe85e3b1759c106aae39b904848466","label":"security-advisories@github.com"},{"url":"https://github.com/izpack/izpack/pull/1193","label":"security-advisories@github.com"},{"url":"https://github.com/izpack/izpack/security/advisories/GHSA-f63g-88cj-hjf9","label":"security-advisories@github.com"},{"url":"https://github.com/izpack/izpack/security/advisories/GHSA-f63g-88cj-hjf9","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-f63g-88cj-hjf9"}],"tags":["nvd","ghsa","maven"],"epss":0.00377,"epssPercentile":0.3144,"aliases":["GHSA-f63g-88cj-hjf9"],"ecosystem":"maven","ingestedAt":"2026-08-26T14:45:08.330Z","slug":"CVE-2026-54550","body":"## Overview\n\nIzPack is a widely used tool for packaging applications on the Java platform as cross-platform installers. In 5.2.6 and earlier, UnpackerBase.unpack() in izpack-installer/src/main/java/com/izforge/izpack/installer/unpacker/UnpackerBase.java obtains an attacker-controlled PackFile targetPath, passes it through IoHelper.translatePath(), which only converts separators, and constructs a File without normalizing parent-directory segments or enforcing destination containment. A malicious installer pack entry containing ../ sequences can therefore write outside the intended installation directory to startup folders, executable search paths, or other locations accessible with the victim's privileges when the victim runs the installer.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-54550)\n\nAffected packages:\n\n- `org.codehaus.izpack:izpack-installer <= 5.2.6`\n\nSource: https://github.com/advisories/GHSA-f63g-88cj-hjf9","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":40.7,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}