LOWCVSS 3.3Vulnerability

CVE-2026-78638

A flaw has been found in peerigon unzip-crx and unzip-crx-3 up to 0.2.0. This affects the function unzip of the file dist/index.js of the component Archive Extraction. Executing a manipulation of the argument destination can lead to path traversal. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Properties

severity
LOW
cvss_severity
LOW
cvss_score
3.3
retrieved_at
2026-09-29T00:56:27+00:00
score
3.3
last_source
NVD
cve_id
CVE-2026-78638
cvss_vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
signal_observed_at
2026-09-29T00:56:27+00:00
vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
published_at
2026-08-25T06:19:01.573
last_modified
2026-09-28T23:10:00.143

Related Entities (2)

HAS_WEAKNESS (1)

→[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

DESCRIBED_BY (1)

→[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-78638 (CVSS 3.3) — Ninja Signal Threat Intelligence | Ninja Signal