Debian Package Tracker
Register | Log in
Subscribe

node-extract-zip

unzip a zip file using pure javascript

Choose email to subscribe with

general
  • source: node-extract-zip (main)
  • version: 2.0.1+ds-4
  • maintainer: Debian Javascript Maintainers (archive) (DMD)
  • uploaders: Andrius Merkys [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.0.1+ds-1
  • oldstable: 2.0.1+ds-4
  • stable: 2.0.1+ds-4
  • testing: 2.0.1+ds-4
  • unstable: 2.0.1+ds-4
versioned links
  • 2.0.1+ds-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.1+ds-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • node-extract-zip
action needed
1 security issue in trixie high

There is 1 open security issue in trixie.

1 important issue:
  • CVE-2026-56876: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Created: 2026-06-27 Last update: 2026-06-27 07:00
1 security issue in sid high

There is 1 open security issue in sid.

1 important issue:
  • CVE-2026-56876: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Created: 2026-06-27 Last update: 2026-06-27 07:00
1 security issue in forky high

There is 1 open security issue in forky.

1 important issue:
  • CVE-2026-56876: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Created: 2026-06-27 Last update: 2026-06-27 07:00
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-56876: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Created: 2026-06-27 Last update: 2026-06-27 07:00
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-56876: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
Created: 2026-06-27 Last update: 2026-06-27 07:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.1).
Created: 2022-12-17 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2022-11-02] node-extract-zip 2.0.1+ds-4 MIGRATED to testing (Debian testing watch)
  • [2022-10-31] Accepted node-extract-zip 2.0.1+ds-4 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-10-15] node-extract-zip 2.0.1+ds-3 MIGRATED to testing (Debian testing watch)
  • [2021-10-12] Accepted node-extract-zip 2.0.1+ds-3 (source) into unstable (Yadd) (signed by: Xavier Guimard)
  • [2021-09-05] node-extract-zip 2.0.1+ds-2 MIGRATED to testing (Debian testing watch)
  • [2021-08-28] Accepted node-extract-zip 2.0.1+ds-2 (source) into unstable (Debian Janitor) (signed by: Jelmer Vernooij)
  • [2020-07-24] node-extract-zip 2.0.1+ds-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-22] Accepted node-extract-zip 2.0.1+ds-1 (source) into unstable (Andrius Merkys)
  • [2020-07-12] Accepted node-extract-zip 2.0.0+ds-1 (source all) into unstable, unstable (Debian FTP Masters) (signed by: Andrius Merkys)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • other distros
  • security tracker
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.0.1+ds-4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing