A AegiFlow
HIGHCVSS 8.6EPSS 0.4%

CVE-2026-56876

extract-zip unvalidated symlink path traversal

Published
2026-06-26
Modified
2026-08-12
EPSS percentile
32%
Aliases
GHSA-jmr9-qjv8-65gv
Sources
github-advisory

Summary

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmextract-zip

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.