CVE-2026-56876
Published Jun 26, 2026extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/pa…
- evidence mentions
- 3
- Buzz score
- 25.4