← Back

CVE-2026-19693

nvd nist
Published: Aug 17, 2026Modified: Aug 27, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: 22e2d327-25fe-45d7-9f0c-dcd23b7108df (Secondary)

Description

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.

References (2)

Source: 22e2d327-25fe-45d7-9f0c-dcd23b7108df
Source: 22e2d327-25fe-45d7-9f0c-dcd23b7108df

Timeline

No history available yet.