CVE-2026-19693: extract-zip allows arbitrary file writes through symlink archive entries
(updated )
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry’s own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-19693 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →