extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Max-mapper
Max-mapper extract-zip
Vendors & Products Max-mapper
Max-mapper extract-zip

Mon, 17 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Title extract-zip arbitrary file write outside the destination directory via a symlink at the final path component
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: seal

Published:

Updated: 2026-08-27T11:29:02.653Z

Reserved: 2026-08-13T07:30:18.584Z

Link: CVE-2026-19693

cve-icon Vulnrichment

Updated: 2026-08-17T16:00:44.064Z

cve-icon NVD

Status : Received

Published: 2026-08-17T14:20:20.737

Modified: 2026-08-27T13:16:57.343

Link: CVE-2026-19693

cve-icon Redhat

Severity : Important

Publid Date: 2026-08-17T13:30:22Z

Links: CVE-2026-19693 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T15:45:03Z

Weaknesses