CVE-2026-3223 Details
Description
Arbitrary file write & potential privilege escalation exploiting zip slip vulnerability in Google Web Designer.
A Zip Slip vulnerability has been identified in Google Web Designer, allowing for arbitrary file write and potential privilege escalation. The issue arises because the application improperly validates file paths when extracting ZIP archives, enabling attackers to exploit path traversal by including `../` sequences. This vulnerability can be exploited by crafting a malicious ZIP file that, when imported into Google Web Designer, writes to sensitive locations on the user's system. If Google Web Designer is run with elevated privileges, this could lead to more severe consequences, such as writing malicious DLLs into system directories for DLL hijacking.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bughunters.google.com/reports/vrp/FJMQGy8oo | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| google web designer | 14.2.2.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 14, 2026 | Initial Analysis | [email protected] |
| Feb 27, 2026 | New CVE Received | [email protected] |