PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19693 max-mapper CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T14:20:20.737Z and has not been modified since then. The extract-zip package through 2.0.1 has a vulnerability where containment-checks only verify the parent directory of each archive entry, not the entry's final path component. This allows an archive with a symlink (targeting outside the destination) followed by a regular file to write through the symlink, resulting in an arbitrary file write outside the destination directory. Affected product deployments should be identified and verified for potential exposure. Developers and administrators using extract-zip package versions up to 2.0.1 should be aware of the potential for arbitrary file writes and take defensive actions. Operators, platforms, vulnerability-management teams, and security teams should assess affected scope and implement compensating controls where necessary.

Vendor
max-mapper
Product
extract-zip
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-17
Original CVE updated
2026-08-27
Advisory published
2026-08-17
Advisory updated
2026-08-27

Who should care

Developers and administrators using extract-zip package versions up to 2.0.1 should be aware of the potential for arbitrary file writes and take defensive actions. Operators, platforms, vulnerability-management teams, and security teams should assess affected scope and implement compensating controls where necessary.

Technical summary

The extract-zip package through 2.0.1 has a vulnerability where containment-checks only verify the parent directory of each archive entry, not the entry's final path component. This allows an archive with a symlink (targeting outside the destination) followed by a regular file to write through the symlink, resulting in an arbitrary file write outside the destination directory. Affected product deployments should be identified and verified for potential exposure.

Defensive priority

High-priority defensive actions are required due to the HIGH CVSS score of 8.1 and potential for arbitrary file writes.

Recommended defensive actions

  • Inventory and verify extract-zip versions up to 2.0.1 for containment-checks
  • Assess affected scope and potential arbitrary file writes
  • Monitor for vendor remediation and apply compensating controls
  • Implement exception tracking and retest
  • Enhance monitoring for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The evidence for this CVE is limited; verify containment-checks in extract-zip through 2.0.1 and assess affected scope; monitor for vendor remediation and apply compensating controls. Limited source detail is available; defensive verification tasks and evidence-limit language are required to ensure accurate understanding of the vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19693 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19693

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19693 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19693

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/max-mapper/extract-zip

    22e2d327-25fe-45d7-9f0c-dcd23b7108df

  • Source reference

    Unverified legacy reference

    URL: https://www.npmjs.com/package/extract-zip

    22e2d327-25fe-45d7-9f0c-dcd23b7108df

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.