What is CVE-2026-17514?
A path traversal vulnerability was identified in ZJONSSON node-unzipper up to version 0.12.3, specifically in the `Extract` function within `lib/extract.js`. This flaw allows local attackers to manipulate file extraction paths, potentially writing files to unintended directories. Users should update to a patched version or apply manual path validation controls.
Azərbaycanca: ZJONSSON node-unzipper kitabxanasının 0.12.3-ə qədər versiyalarında `lib/extract.js` faylındakı `Extract` funksiyasında path traversal zəifliyi aşkarlanıb. Bu qüsur lokal girişlə arxivdən fayl çıxararkən kənar qovluqlara yazmağa imkan verir. İstifadəçilərə kitabxananı təhlükəsiz versiyaya yeniləmələri və ya əl ilə yoxlamalar əlavə etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which function of the ZJONSSON node-unzipper library was CVE-2026-17514 identified?
This path traversal vulnerability was identified in the `Extract` function within the `lib/extract.js` file.
What measures are recommended to mitigate CVE-2026-17514?
Users are advised to update to a patched version or apply manual path validation controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.