VDB
CVE-2026-56876
CVE-2026-56876
PUBLISHED
CVSS 8.1 HIGH
Reported by cisa-cg · Published June 26, 2026
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Risk Scores
CVSS 3.1
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| max-mapper | extract-zip | 0 |
| npm | extract-zip | 0 |
| max-mapper | extract-zip | 0, 0, 0 |
Timeline
- Jun 26, 2026 CVE Published
- Jun 27, 2026 EPSS Score
- Jun 27, 2026 Coalition ESS Score
- Jun 29, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 21, 2026 Distribution Patch
- Aug 21, 2026 Security Advisory
- Aug 26, 2026 EPSS Score
References
- url third-party-advisory
- url third-party-advisory
- url vdb-entry
- https://nvd.nist.gov/vuln/detail/CVE-2026-56876 advisory
- https://github.com/advisories/GHSA-jmr9-qjv8-65gv advisory