Information on source package node-extract-zip

Available versions

ReleaseVersion
bullseye2.0.1+ds-1
bookworm2.0.1+ds-4
trixie2.0.1+ds-4
forky2.0.1+ds-4
sid2.0.1+ds-4

Open issues

BugbullseyebookwormtrixieforkysidDescription
CVE-2026-56876vulnerable (no DSA, postponed)vulnerable (no DSA, postponed)vulnerable (no DSA)vulnerablevulnerableextract-zip does not validate symlink targets when extracting zip arch ...
CVE-2026-19693vulnerablevulnerablevulnerable (no DSA)vulnerablevulnerableextract-zip through 2.0.1 containment-checks only the parent directory ...

Search for package or bug name: Reporting problems