EMQX plugin install zip slip
A vulnerability was identified in the EMQX plugin installation process, known as zip slip, which could allow attackers to exploit the system by manipulating file paths during the extraction of zip files. This issue has been addressed in recent pull requests that implement a fix along with additional security measures such as TTL and sha256-pinning for the install allowlist.
EMQX is the world's most scalable open-source MQTT broker, capable of handling more than 100 million concurrent IoT connections per cluster, and is used by Fortune 500 companies including HPE, Volkswagen, SAIC, Ericsson, and Siemens. Powering critical IoT infrastructure across automotive, manufacturing, energy, and smart-city deployments, EMQX has more than 14,000 GitHub stars and is the de-facto MQTT engine for industrial IoT.