CVE-2026-56876

NameCVE-2026-56876
Descriptionextract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
node-extract-zip (PTS)bullseye2.0.1+ds-1vulnerable
forky, sid, bookworm, trixie2.0.1+ds-4vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
node-extract-zipsource(unstable)(unfixed)

Notes

https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf

Search for package or bug name: Reporting problems