extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Max-mapper
Max-mapper extract-zip
Vendors & Products Max-mapper
Max-mapper extract-zip

Mon, 17 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Title extract-zip arbitrary file write outside the destination directory via a symlink at the final path component
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: seal

Published:

Updated: 2026-08-17T16:00:48.858Z

Reserved: 2026-08-13T07:30:18.584Z

Link: CVE-2026-19693

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T14:20:20.737

Modified: 2026-08-17T16:16:52.813

Link: CVE-2026-19693

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:45:03Z

Weaknesses