# How Wand-Enhancer Prevents Zip-Slip Vulnerability During ASAR Extraction

> Learn how Wand-Enhancer safeguards ASAR extraction by validating file paths with Extensions.IsPathInside, effectively preventing zip-slip vulnerabilities. Secure your extraction process.

- Repository: [k1tbyte/Wand-Enhancer](https://github.com/k1tbyte/Wand-Enhancer)
- Tags: how-to-guide
- Published: 2026-09-01

---

**Wand-Enhancer prevents the zip-slip vulnerability by validating that every extracted file path remains within the destination directory using the `Extensions.IsPathInside` guard before writing any data.**

The k1tbyte/Wand-Enhancer repository provides secure ASAR archive extraction capabilities that defend against directory traversal attacks. When extracting Electron application archives, the tool implements a strict path validation mechanism that normalizes file paths and verifies containment within the target folder. This ensures that malicious archive entries containing `..` sequences cannot escape the extraction root and write files to arbitrary system locations.

## The ASAR Extraction Pipeline

In [`AsarSharp/AsarExtractor.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/AsarSharp/AsarExtractor.cs), the `ExtractAll` method processes archives through a secure pipeline that validates every entry before writing to disk. The implementation iterates through the ASAR filesystem using `foreach (var fullPath in filenames)` and constructs destination paths using `Path.Combine(dest, filename)`.

The critical security check occurs at lines 44-53, where the code validates the resolved path before extraction:

```csharp
var destFilename = Path.Combine(dest, filename);

if (!Extensions.IsPathInside(dest, destFilename))
{
    throw new InvalidOperationException($"{fullPath}: file \"{destFilename}\" writes out of the package");
}

```

If the guard passes, the extractor proceeds to `ExtractFile`, `ExtractLink`, or `EnsureDirectory` depending on the entry type. If validation fails, the `InvalidOperationException` immediately aborts processing for that entry, preventing any file system write operations outside the extraction root.

## How the Path Traversal Guard Works

The security mechanism relies on the `IsPathInside` helper method implemented in [`AsarSharp/Utils/Extensions.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/AsarSharp/Utils/Extensions.cs). This utility normalizes both the destination root and the candidate file path using `Path.GetFullPath` to resolve any relative components or symbolic links.

The normalization process eliminates malicious traversal sequences by converting paths like `../../evil.exe` into absolute representations that reveal their true location outside the target directory. After normalization, the method trims trailing separators via `TrimTrailingSeparators` and performs a prefix comparison to confirm the candidate path either matches the root exactly or begins with the root followed by a directory separator.

### The IsPathInside Implementation

```csharp
public static bool IsPathInside(string root, string candidate)
{
    string fullRoot = TrimTrailingSeparators(Path.GetFullPath(root));
    string fullCandidate = TrimTrailingSeparators(Path.GetFullPath(candidate));

    if (string.Equals(fullRoot, fullCandidate, StringComparison.OrdinalIgnoreCase))
        return true;

    return fullCandidate.Length > fullRoot.Length
           && fullCandidate.StartsWith(fullRoot, StringComparison.OrdinalIgnoreCase)
           && IsSeparator(fullCandidate[fullRoot.Length]);
}

```

This approach ensures that normalized paths containing parent directory references fail the prefix check, effectively neutralizing zip-slip attacks before file system write operations commence.

## Practical Code Examples

### Basic Secure Extraction

To extract an ASAR archive safely using the built-in protection:

```csharp
using AsarSharp;

string archivePath = @"C:\Games\Wand\resources\app.asar";
string outputDir = @"C:\Temp\wand-extracted";

// ExtractAll automatically validates every entry path
AsarExtractor.ExtractAll(archivePath, outputDir);

```

### Handling Malicious Archive Entries

When processing archives containing malicious traversal paths, the extractor throws a descriptive exception:

```csharp
try
{
    AsarExtractor.ExtractAll(archivePath, outputDir);
}
catch (InvalidOperationException ex)
{
    // Output format: ../../evil.txt: file "C:\evil.txt" writes out of the package
    Console.WriteLine($"Security violation detected: {ex.Message}");
}

```

### Manual Path Validation

You can also use the validation logic directly for custom extraction workflows:

```csharp
using AsarSharp.Utils;

string root = @"C:\Temp\extract";
string suspiciousPath = @"C:\Temp\extract\sub\..\..\evil.exe";

bool isSafe = Extensions.IsPathInside(root, suspiciousPath);
// Returns false - path escapes the root directory

```

## Summary

- **Path Normalization**: Both destination and candidate paths undergo `Path.GetFullPath` normalization in `Extensions.IsPathInside` to resolve relative segments and symbolic links.
- **Containment Verification**: The method performs prefix-based validation using `StringComparison.OrdinalIgnoreCase` and separator checking to ensure extracted files remain within the designated root folder.
- **Immediate Rejection**: Malicious entries trigger an `InvalidOperationException` at [`AsarExtractor.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/AsarExtractor.cs) lines 44-53, preventing any file system write operations outside the extraction boundary.
- **Cross-Platform Support**: The implementation handles platform-specific path separators through the `IsSeparator` helper, ensuring consistent protection across Windows and Unix systems.

## Frequently Asked Questions

### What is the zip-slip vulnerability in ASAR extraction?

The zip-slip vulnerability occurs when archive extraction software fails to validate destination paths, allowing malicious archive entries containing `..` sequences to write files outside the intended extraction directory. This can lead to arbitrary file overwrites, system compromise, or remote code execution when attackers overwrite critical system files or place executables in startup folders.

### Which method in Wand-Enhancer provides the zip-slip protection?

The `Extensions.IsPathInside` method in [`AsarSharp/Utils/Extensions.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/AsarSharp/Utils/Extensions.cs) provides the core protection logic, while the `AsarExtractor.ExtractAll` method in [`AsarSharp/AsarExtractor.cs`](https://github.com/k1tbyte/Wand-Enhancer/blob/main/AsarSharp/AsarExtractor.cs) implements the enforcement at lines 44-53 by calling the guard before invoking `ExtractFile`, `ExtractLink`, or `EnsureDirectory`.

### How does the path validation handle case sensitivity?

The implementation uses `StringComparison.OrdinalIgnoreCase` when comparing normalized paths, ensuring the zip-slip protection works correctly on case-insensitive file systems like Windows NTFS while maintaining security on case-sensitive systems like Linux ext4.

### At which stage does the extraction process check for zip-slip attempts?

The validation occurs during the enumeration phase in `AsarExtractor.ExtractAll` immediately after constructing the destination path via `Path.Combine` but before executing any file write operations. This pre-write validation ensures that no disk operations occur for malicious entries, effectively preventing directory traversal outside the extraction root.