Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.1
CVE-2026-19693
- EPSS 0.28%
- Veröffentlicht 17.08.2026 13:30:22
- Zuletzt bearbeitet 17.08.2026 16:16:52
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination...
8.6
CVE-2026-56876
- EPSS 0.39%
- Veröffentlicht 26.06.2026 16:44:29
- Zuletzt bearbeitet 06.07.2026 13:25:43
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowin...
1