Skip to main content

Vendor archive

max-mapper CVEs

Beta · best-effort

1 CVEs tagged to vendor max-mapper0 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-56876

Published Jun 26, 2026

extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/pa…

CVSS 8.6 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort
Showing 1-1 of 1 CVEsPage 1 of 1