Severity: high
CVE: CVE-2026-19693
Package: extract-zip @ 2.0.1
Vulnerable range: <=2.0.1
Patched in: <0.0.0
Dep paths:
artifacts__void-client>puppeteer-core>@puppeteer/browsers>extract-zip
extract-zip allows arbitrary file writes through symlink archive entries
Reference: GHSA-7pqw-9j4j-h8q3
Filed automatically by .github/workflows/pnpm-audit.yml. The fix
work for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md §11 limitation 4 for the
policy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to scripts/audit/ignore-list.json
with a written reachability rationale and a re-evaluation date.
Severity: high
CVE: CVE-2026-19693
Package:
extract-zip@2.0.1Vulnerable range:
<=2.0.1Patched in:
<0.0.0Dep paths:
artifacts__void-client>puppeteer-core>@puppeteer/browsers>extract-zipReference: GHSA-7pqw-9j4j-h8q3
Filed automatically by
.github/workflows/pnpm-audit.yml. The fixwork for this CVE belongs in its own task; see
docs/security-audit-public-2026-04.md§11 limitation 4 for thepolicy. Either bump the affected dep (closes this issue on the next
scheduled run) or add an entry to
scripts/audit/ignore-list.jsonwith a written reachability rationale and a re-evaluation date.