Launchpad.net

CVE 2017-8314

Directory Traversal in Zip Extraction built-in function in Kodi 17.1 and earlier allows arbitrary file write on disk via a Zip file as subtitles.

See the CVE page on Mitre.org for more details.