GHSA-7pqw-9j4j-h8q3
Dashboard / Vulnerabilities / GHSA-7pqw-9j4j-h8q3
Summary: extract-zip allows arbitrary file writes through symlink archive entries
Details: extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
References: https://nvd.nist.gov/vuln/detail/CVE-2026-19693, https://github.com/max-mapper/extract-zip/pull/160, https://github.com/max-mapper/extract-zip, https://www.npmjs.com/package/extract-zip
Affected packages
Package
Name: extract-zip
Purl: pkg:npm/extract-zip
Affected ranges
Type: SEMVER
Events:
