B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-56876 - extract-zip unvalidated symlink path traversal

CVE ID :CVE-2026-56876 Published : June 26, 2026, 4:44 p.m. | 4 hours, 27 minutes ago Description :extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd',...

Original-Artikel öffnen Zurück zur Übersicht