Unknown · Extract-Zip · CVE-2026-56876
**Name of the Vulnerable Software and Affected Versions**
extract-zip (affected versions not specified)
**Description**
The software fails to validate symlink targets during the extraction of zip archives. A malicious zip file containing a symlink with a relative path can be used to point outside the intended extraction directory, potentially allowing an attacker to read or write arbitrary files on the system.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.