[security][CVE-2026-56876] extract-zip in desktop build chain #164
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
New active CVE detected by the
cve-security-triageautomation.CVE-2026-56876extract-zip@2.0.1@electron/packager -> @electron-forge/* -> apps/desktopProject impact
The desktop build and packaging chain resolves a vulnerable
extract-ziprelease through Electron packaging. The advisory says symlink targets in extracted zip content are not validated, which can let a crafted archive escape the intended destination directory. This does not change the deployed web or API runtime, but it does affect desktop packaging surfaces that unpack zip content.Recommended remediation
extract-zip@2.0.1Run counters
Sources