CVE-2026-17514

Source
https://cve.org/CVERecord?id=CVE-2026-17514
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17514.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-17514
Published
2026-07-27T13:15:09.434Z
Modified
2026-07-29T03:30:23.916353160Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
ZJONSSON node-unzipper extract.js Extract path traversal
Details

A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. Affected by this vulnerability is the function Extract of the file lib/extract.js. This manipulation causes path traversal. The attack requires local access. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/17xxx/CVE-2026-17514.json",
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/zjonsson/node-unzipper

Affected ranges

Type
GIT
Repo
https://github.com/zjonsson/node-unzipper
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "0.12.0"
        },
        {
            "last_affected": "0.12.0"
        },
        {
            "introduced": "0.12.1"
        },
        {
            "last_affected": "0.12.1"
        },
        {
            "introduced": "0.12.2"
        },
        {
            "last_affected": "0.12.2"
        },
        {
            "introduced": "0.12.3"
        },
        {
            "last_affected": "0.12.3"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

0.*
0.12.0
0.12.1
0.12.2
0.12.3
v0.*
v0.12.0
v0.12.1
v0.12.2
v0.12.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-17514.json"