extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 17 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Max-mapper
Max-mapper extract-zip |
|
| Vendors & Products |
Max-mapper
Max-mapper extract-zip |
Mon, 17 Aug 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory. | |
| Title | extract-zip arbitrary file write outside the destination directory via a symlink at the final path component | |
| Weaknesses | CWE-22 CWE-59 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: seal
Published:
Updated: 2026-08-17T16:00:48.858Z
Reserved: 2026-08-13T07:30:18.584Z
Link: CVE-2026-19693
No data.
Status : Received
Published: 2026-08-17T14:20:20.737
Modified: 2026-08-17T16:16:52.813
Link: CVE-2026-19693
No data.
OpenCVE Enrichment
Updated: 2026-08-17T15:45:03Z