LOW
peerigon
CVE published 2026-08-25
CVE-2026-78638
A path traversal vulnerability was found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The vulnerability allows attackers to write files to arbitrary locations, potentially leading to un [truncated]