[security][CVE-2026-19693] extract-zip in desktop packaging #174
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Newly reported active High CVE from the 2026-09-16 scan. New means not previously reported by this automation; some disclosures predate this run. Correction: earlier scans incorrectly dropped Trivy status
fixed, which means a patch is available, not installed.CVE: CVE-2026-19693
Severity: High. CVSS: ghsa: 8.1, redhat: 8.1
Affected versions
Project impact
apps/desktop uses Electron Forge and @electron/packager@18.4.4. Its dist/unzip.js calls extract-zip on Electron ZIP archives. A malicious or compromised archive with a symlink followed by a same-name file can write outside the extraction directory under the build user. This is build/packaging exposure, not a demonstrated web/API request exploit.
Advisory description
extract-zip through 2.0.1 containment-checks only the parent directory of each archive entry and never the entry's own final path component, so an archive containing two entries with identical names - a symlink whose target is outside the destination, followed by a regular file - writes through the planted symlink and yields an arbitrary file write outside the destination directory.
Remediation
No patched extract-zip version is listed. Move to an upstream packaging release with a safe extractor or reviewed patch. Until then, accept only verified trusted Electron archives and isolate packaging with minimal filesystem permissions. Related #164 concerns a different CVE and does not resolve this one.
Run counters, globally deduplicated by CVE ID
unaddressed critical CVEs: 6
unaddressed medium/low CVEs: 184
unaddressed total CVEs: 271
These are unresolved installed-version matches after explicit exclusions, not a claim that every inherited component is remotely exploitable. One UNKNOWN-severity record is retained separately and excluded from the requested severity total. Python requirements and apt-installed Python packages are unpinned, so their deployed versions cannot be established from this repository.
Resolution checks
Paginated all 171 Forgejo issue records and 101 PRs; checked local all-ref history. No matching CVE report or clear fixing change was found for this CVE. Its CVE registry state is PUBLISHED without a disputed tag. Existing reports for other flaws in the same component do not establish a fix for this one.
Sources