AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T14:20:20.737Z and has not been modified since then. The extract-zip package through 2.0.1 has a vulnerability where containment-checks only verify the parent directory of each archive entry, not the entry's final path component. This allows an archive with a symlink (targeting outside the destina [truncated]
CVE-2026-56876 is a HIGH severity vulnerability in extract-zip due to a lack of symlink target validation when extracting zip archives. This issue allows an attacker to create symlinks with relative paths that can point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files. The vulnerability was published on June 26, 2026, and last modif [truncated]