CVE-2026-19693

NameCVE-2026-19693
Descriptionextract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-extract-zip (PTS)bullseye2.0.1+ds-1vulnerable
forky, sid, bookworm, trixie2.0.1+ds-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-extract-zipsource(unstable)(unfixed)

Notes

https://github.com/max-mapper/extract-zip/pull/160

Search for package or bug name: Reporting problems