A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extraction directory and write files to arbitrary locations on the server, potentially achieve arbitrary code execution due to improper validation of archive entry paths before writing files to disk which could result in full system compromise.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-14947 is a critical vulnerability affecting systems that process ZIP archives without properly validating extraction paths. When an attacker uploads a specially crafted ZIP file containing directory traversal sequences (such as ../), the archive extraction logic fails to sanitize these paths, allowing files to be written outside the intended extraction directory to arbitrary locations on the server. This vulnerability is particularly dangerous because it can lead to arbitrary code execution and full system compromise when malicious files are written to executable directories or configuration locations. Organizations running web applications, file processing services, or any systems accepting uploaded archives from untrusted sources are at risk, especially those with high-privilege processes handling these archives.
While CVE-2026-14947 doesn't map directly to MITRE ATT&CK techniques, Casky's platform would detect the attack patterns through its 754 mapped security skills by identifying suspicious file operations and path manipulation behaviors. Practitioners using Casky would observe findings related to CWE-24 (improper restriction of rendered UI layers or frames) and path traversal indicators—specifically detecting when extraction processes attempt to write files with absolute paths or sequences that escape sandbox boundaries. Claude's extended reasoning capabilities would correlate multiple signals: detection of ../sequences in file names, unusual write operations to system directories, and permission escalations following file extraction. Security teams would see anomalies in file operation logs showing attempted writes to sensitive locations like /etc, /var, or web root directories, enabling them to identify exploitation attempts before arbitrary code execution occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-14947. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation