[Pkg-javascript-devel] Bug#1141501: node-extract-zip: CVE-2026-56876
Salvatore Bonaccorso
carnil at debian.org
Sun Jul 5 16:13:53 BST 2026
Source: node-extract-zip
Version: 2.0.1+ds-4
Severity: important
Tags: security upstream
X-Debbugs-Cc: carnil at debian.org, Debian Security Team <team at security.debian.org>
Hi,
The following vulnerability was published for node-extract-zip.
CVE-2026-56876[0]:
| extract-zip does not validate symlink targets when extracting zip
| archives. When processing a malicious zip file containing a symlink
| with a relative path like '../../../../etc/passwd', extract-zip will
| extract the symlink without validation, allowing it to point outside
| the extraction directory. Depending on how extract-zip is used, an
| attacker could read or write to arbitrary files.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-56876
https://www.cve.org/CVERecord?id=CVE-2026-56876
[1] https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf
Regards,
Salvatore
More information about the Pkg-javascript-devel
mailing list