PT-2026-76655 · Pypi · Extract-Zip

·

CVE-2026-19693

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions extract-zip versions prior to 2.0.2
Description Containment checks only verify the parent directory of each archive entry and ignore the entry's own final path component. This allows an archive containing two entries with identical names—a symlink targeting a location outside the destination followed by a regular file—to write through the planted symlink, resulting in an arbitrary file write outside the destination directory.
Recommendations Update to version 2.0.2 or later.

Exploit

Fix

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19693
GHSA-7PQW-9J4J-H8Q3

Affected Products

Extract-Zip