[security][CVE-2026-56876] extract-zip in desktop build chain #164

Open
opened 2026-08-25 13:20:29 +00:00 by dirtydishes · 0 comments
Owner

New active CVE detected by the cve-security-triage automation.

  • CVE: CVE-2026-56876
  • Component: extract-zip@2.0.1
  • In-repo path: @electron/packager -> @electron-forge/* -> apps/desktop
  • Severity: High (CVSS 8.1)
  • Fixed version: No patched release listed on the advisory as of 2026-08-25

Project impact

The desktop build and packaging chain resolves a vulnerable extract-zip release through Electron packaging. The advisory says symlink targets in extracted zip content are not validated, which can let a crafted archive escape the intended destination directory. This does not change the deployed web or API runtime, but it does affect desktop packaging surfaces that unpack zip content.

Recommended remediation

  • Prefer an upstream Electron packaging release that removes or patches extract-zip@2.0.1
  • If no upstream fix is available yet, avoid feeding untrusted zip content into the packaging flow and track the upstream patch closely
  • Re-run the CVE scan once the Electron packaging chain changes

Run counters

  • unaddressed critical CVEs: 3
  • unaddressed medium/low CVEs: 77
  • unaddressed total CVEs: 95

Sources

New active CVE detected by the `cve-security-triage` automation. - CVE: `CVE-2026-56876` - Component: `extract-zip@2.0.1` - In-repo path: `@electron/packager -> @electron-forge/* -> apps/desktop` - Severity: High (CVSS 8.1) - Fixed version: No patched release listed on the advisory as of 2026-08-25 Project impact The desktop build and packaging chain resolves a vulnerable `extract-zip` release through Electron packaging. The advisory says symlink targets in extracted zip content are not validated, which can let a crafted archive escape the intended destination directory. This does not change the deployed web or API runtime, but it does affect desktop packaging surfaces that unpack zip content. Recommended remediation - Prefer an upstream Electron packaging release that removes or patches `extract-zip@2.0.1` - If no upstream fix is available yet, avoid feeding untrusted zip content into the packaging flow and track the upstream patch closely - Re-run the CVE scan once the Electron packaging chain changes Run counters - unaddressed critical CVEs: 3 - unaddressed medium/low CVEs: 77 - unaddressed total CVEs: 95 Sources - https://github.com/advisories/GHSA-jmr9-qjv8-65gv - https://nvd.nist.gov/vuln/detail/CVE-2026-56876 - https://www.cve.org/CVERecord?id=CVE-2026-56876
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#164
No description provided.