How Wand-Enhancer Prevents Zip-Slip Vulnerability During ASAR Extraction

Wand-Enhancer prevents the zip-slip vulnerability by validating that every extracted file path remains within the destination directory using the Extensions.IsPathInside guard before writing any data.

The k1tbyte/Wand-Enhancer repository provides secure ASAR archive extraction capabilities that defend against directory traversal attacks. When extracting Electron application archives, the tool implements a strict path validation mechanism that normalizes file paths and verifies containment within the target folder. This ensures that malicious archive entries containing .. sequences cannot escape the extraction root and write files to arbitrary system locations.

The ASAR Extraction Pipeline

In AsarSharp/AsarExtractor.cs, the ExtractAll method processes archives through a secure pipeline that validates every entry before writing to disk. The implementation iterates through the ASAR filesystem using foreach (var fullPath in filenames) and constructs destination paths using Path.Combine(dest, filename).

The critical security check occurs at lines 44-53, where the code validates the resolved path before extraction:

var destFilename = Path.Combine(dest, filename);

if (!Extensions.IsPathInside(dest, destFilename))
{
    throw new InvalidOperationException($"{fullPath}: file \"{destFilename}\" writes out of the package");
}

If the guard passes, the extractor proceeds to ExtractFile, ExtractLink, or EnsureDirectory depending on the entry type. If validation fails, the InvalidOperationException immediately aborts processing for that entry, preventing any file system write operations outside the extraction root.

How the Path Traversal Guard Works

The security mechanism relies on the IsPathInside helper method implemented in AsarSharp/Utils/Extensions.cs. This utility normalizes both the destination root and the candidate file path using Path.GetFullPath to resolve any relative components or symbolic links.

The normalization process eliminates malicious traversal sequences by converting paths like ../../evil.exe into absolute representations that reveal their true location outside the target directory. After normalization, the method trims trailing separators via TrimTrailingSeparators and performs a prefix comparison to confirm the candidate path either matches the root exactly or begins with the root followed by a directory separator.

The IsPathInside Implementation

public static bool IsPathInside(string root, string candidate)
{
    string fullRoot = TrimTrailingSeparators(Path.GetFullPath(root));
    string fullCandidate = TrimTrailingSeparators(Path.GetFullPath(candidate));

    if (string.Equals(fullRoot, fullCandidate, StringComparison.OrdinalIgnoreCase))
        return true;

    return fullCandidate.Length > fullRoot.Length
           && fullCandidate.StartsWith(fullRoot, StringComparison.OrdinalIgnoreCase)
           && IsSeparator(fullCandidate[fullRoot.Length]);
}

This approach ensures that normalized paths containing parent directory references fail the prefix check, effectively neutralizing zip-slip attacks before file system write operations commence.

Practical Code Examples

Basic Secure Extraction

To extract an ASAR archive safely using the built-in protection:

using AsarSharp;

string archivePath = @"C:\Games\Wand\resources\app.asar";
string outputDir = @"C:\Temp\wand-extracted";

// ExtractAll automatically validates every entry path
AsarExtractor.ExtractAll(archivePath, outputDir);

Handling Malicious Archive Entries

When processing archives containing malicious traversal paths, the extractor throws a descriptive exception:

try
{
    AsarExtractor.ExtractAll(archivePath, outputDir);
}
catch (InvalidOperationException ex)
{
    // Output format: ../../evil.txt: file "C:\evil.txt" writes out of the package
    Console.WriteLine($"Security violation detected: {ex.Message}");
}

Manual Path Validation

You can also use the validation logic directly for custom extraction workflows:

using AsarSharp.Utils;

string root = @"C:\Temp\extract";
string suspiciousPath = @"C:\Temp\extract\sub\..\..\evil.exe";

bool isSafe = Extensions.IsPathInside(root, suspiciousPath);
// Returns false - path escapes the root directory

Summary

  • Path Normalization: Both destination and candidate paths undergo Path.GetFullPath normalization in Extensions.IsPathInside to resolve relative segments and symbolic links.
  • Containment Verification: The method performs prefix-based validation using StringComparison.OrdinalIgnoreCase and separator checking to ensure extracted files remain within the designated root folder.
  • Immediate Rejection: Malicious entries trigger an InvalidOperationException at AsarExtractor.cs lines 44-53, preventing any file system write operations outside the extraction boundary.
  • Cross-Platform Support: The implementation handles platform-specific path separators through the IsSeparator helper, ensuring consistent protection across Windows and Unix systems.

Frequently Asked Questions

What is the zip-slip vulnerability in ASAR extraction?

The zip-slip vulnerability occurs when archive extraction software fails to validate destination paths, allowing malicious archive entries containing .. sequences to write files outside the intended extraction directory. This can lead to arbitrary file overwrites, system compromise, or remote code execution when attackers overwrite critical system files or place executables in startup folders.

Which method in Wand-Enhancer provides the zip-slip protection?

The Extensions.IsPathInside method in AsarSharp/Utils/Extensions.cs provides the core protection logic, while the AsarExtractor.ExtractAll method in AsarSharp/AsarExtractor.cs implements the enforcement at lines 44-53 by calling the guard before invoking ExtractFile, ExtractLink, or EnsureDirectory.

How does the path validation handle case sensitivity?

The implementation uses StringComparison.OrdinalIgnoreCase when comparing normalized paths, ensuring the zip-slip protection works correctly on case-insensitive file systems like Windows NTFS while maintaining security on case-sensitive systems like Linux ext4.

At which stage does the extraction process check for zip-slip attempts?

The validation occurs during the enumeration phase in AsarExtractor.ExtractAll immediately after constructing the destination path via Path.Combine but before executing any file write operations. This pre-write validation ensures that no disk operations occur for malicious entries, effectively preventing directory traversal outside the extraction root.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →