Package
gemini-cli
Component
extract-zip
Latest update
8.1
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Impact
CVE-2026-56876 (GHSA-jmr9-qjv8-65gv, HIGH): unvalidated symlink path traversal in the extract-zip npm package. A crafted zip archive can contain a symlink entry whose target is not validated during extraction, allowing a symlink to be created outside the intended extraction directory.
This package bundles extract-zip 2.0.1. extract-zip's latest and final published release is 2.0.1 (June 2020); the project is no longer actively maintained and no fixed version has been published upstream — the advisory lists no first-patched version and the vulnerable range covers all releases (<= 2.0.1). Because no upstream release resolves the issue, it cannot currently be remediated by a dependency upgrade.
This advisory will be updated when a fixed release of extract-zip (> 2.0.1) becomes available upstream.
References:
Batch: 2026-08-27-A
Status