{"id":"GHSA-7pqw-9j4j-h8q3","summary":"extract-zip allows arbitrary file writes through symlink archive entries","details":"extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.","aliases":["CVE-2026-19693"],"modified":"2026-09-08T21:10:57.608811Z","published":"2026-08-17T15:30:40Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-09-08T20:42:52Z","nvd_published_at":"2026-08-17T14:20:20Z","cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-19693"},{"type":"WEB","url":"https://github.com/max-mapper/extract-zip/pull/160"},{"type":"PACKAGE","url":"https://github.com/max-mapper/extract-zip"},{"type":"WEB","url":"https://www.npmjs.com/package/extract-zip"}],"affected":[{"package":{"name":"extract-zip","ecosystem":"npm","purl":"pkg:npm/extract-zip"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-7pqw-9j4j-h8q3/GHSA-7pqw-9j4j-h8q3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}