[security][CVE-2026-19693] extract-zip in desktop packaging #174

Open
opened 2026-09-16 13:22:48 +00:00 by dirtydishes · 0 comments
Owner

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status fixed, which means a patch is available, not installed.

CVE: CVE-2026-19693
Severity: High. CVSS: ghsa: 8.1, redhat: 8.1

Affected versions

  • extract-zip@2.0.1 in bun.lock and deployment/docker/workspace-root/bun.lock

Project impact

apps/desktop uses Electron Forge and @electron/packager@18.4.4. Its dist/unzip.js calls extract-zip on Electron ZIP archives. A malicious or compromised archive with a symlink followed by a same-name file can write outside the extraction directory under the build user. This is build/packaging exposure, not a demonstrated web/API request exploit.

Advisory description

extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.

Remediation

No patched extract-zip version is listed. Move to an upstream packaging release with a safe extractor or reviewed patch. Until then, accept only verified trusted Electron archives and isolate packaging with minimal filesystem permissions. Related #164 concerns a different CVE and does not resolve this one.

Run counters, globally deduplicated by CVE ID

unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271

These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.

Resolution checks

Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.

Sources

Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status `fixed`, which means a patch is available, not installed. CVE: CVE-2026-19693 Severity: High. CVSS: ghsa: 8.1, redhat: 8.1 Affected versions - extract-zip@2.0.1 in bun.lock and deployment/docker/workspace-root/bun.lock Project impact apps/desktop uses Electron Forge and @electron/packager@18.4.4. Its dist/unzip.js calls extract-zip on Electron ZIP archives. A malicious or compromised archive with a symlink followed by a same-name file can write outside the extraction directory under the build user. This is build/packaging exposure, not a demonstrated web/API request exploit. Advisory description extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory. Remediation No patched extract-zip version is listed. Move to an upstream packaging release with a safe extractor or reviewed patch. Until then, accept only verified trusted Electron archives and isolate packaging with minimal filesystem permissions. Related #164 concerns a different CVE and does not resolve this one. Run counters, globally deduplicated by CVE ID unaddressed critical CVEs: 6 unaddressed medium/low CVEs: 184 unaddressed total CVEs: 271 These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository. Resolution checks Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one. Sources - https://www.cve.org/CVERecord?id=CVE-2026-19693 - https://nvd.nist.gov/vuln/detail/CVE-2026-19693
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#174
No description provided.