๐Ÿ” CVE Alert

CVE-2026-19693

HIGH 8.1

extract-zip arbitrary file write outside the destination directory via a symlink at the final path component

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.

Vendor max-mapper
Product extract-zip
Published Aug 17, 2026
Stay Ahead of the Next One

Get instant alerts for max-mapper extract-zip

Be the first to know when new high vulnerabilities affecting max-mapper extract-zip are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—