VYPR

extract-zip

by Extract Zip

CVEs (1)

  • CVE-2026-56876Jun 27, 2026
    risk 0.00cvss epss

    extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the…