What is CVE-2026-19693?
CVE-2026-19693 is a Zip Slip vulnerability in extract-zip through version 2.0.1. It only validates the parent directory of each archive entry, not the final path component, allowing a symlink followed by a regular file with the same name to write outside the destination. Users should upgrade to the latest version or switch to a secure alternative for archive extraction.
Azərbaycanca: CVE-2026-19693 zəifliyi extract-zip 2.0.1 və əvvəlki versiyalarda aşkarlanıb. Bu, arxiv faylların çıxarılması zamanı yalnız üst qovluğun yoxlanıldığı, fayl adının özünün isə nəzarətdən kənar qaldığı üçün simvolik keçidlər vasitəsilə məqsəd qovluqdan kənara yazmağa imkan verən Zip Slip hücumudur. İstifadəçilər dərhal ən son versiyaya yeniləməli və ya arxiv emalı üçün alternativ təhlükəsiz kitabxanalara keçməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
What is CVE-2026-19693 and which versions are affected?
CVE-2026-19693 is a Zip Slip vulnerability in extract-zip through version 2.0.1. It allows writing outside the destination directory via symlinks because only the parent directory is validated, not the final path component.
How can I protect against CVE-2026-19693?
To protect against this vulnerability, users should immediately upgrade to the latest version of extract-zip or switch to a secure alternative for archive extraction.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.