CVE-2023-50255
NixOS vulnerability analysis and mitigation

Overview

Deepin-Compressor, the default archive manager of Deepin Linux OS, was found to contain a path traversal vulnerability (CVE-2023-50255) prior to version 5.12.21. The vulnerability was discovered and reported by security researcher Febin, with a CVSS v3.1 score of 9.3 (CRITICAL) according to GitHub's assessment (GitHub Advisory).

Technical details

The vulnerability stems from improper validation of file names during the decompression of zip archives. When processing archive contents, the application fails to properly sanitize file paths, allowing attackers to use '../' prefixes in filenames to achieve path traversal. This vulnerability is classified under multiple CWE categories including CWE-23 (Relative Path Traversal), CWE-22 (Path Traversal), and CWE-26 (Path Traversal: '/dir/../filename') (NVD).

Impact

The vulnerability enables arbitrary file writing capabilities and can lead to Remote Code Execution (RCE) on the target system. Attackers can exploit this flaw to place malicious desktop entries under the ~/.config/autostart directory, which would execute upon system startup. This presents a significant security risk as it allows attackers to gain unauthorized system access and execute malicious code (Security Online).

Mitigation and workarounds

Users are strongly advised to update to Deepin-Compressor version 5.12.21 or later, which contains the fix for this vulnerability. The patch implements proper validation of file paths during archive extraction. There are no known workarounds for affected versions (NVD).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-22783HIGH8.1
  • NixOSNixOS
  • iris
NoYesJan 12, 2026
CVE-2026-0821MEDIUM6.9
  • NixOSNixOS
  • quickjs
NoNoJan 10, 2026
CVE-2025-68949MEDIUM5.3
  • NixOSNixOS
  • n8n
NoYesJan 13, 2026
CVE-2026-22784LOW2.3
  • NixOSNixOS
  • lychee
NoYesJan 12, 2026
CVE-2026-23497LOW1.3
  • NixOSNixOS
  • learning
NoYesJan 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management