CVE-2026-30973 | appium support up to 7.0.5 zip.js extractAllTo path traversal (GHSA-rfx7-4xw3-gh4m)
A vulnerability was found in appium support up to 7.0.5 and classified as critical. Affected is the function extractAllTo in the library packages/support/lib/zip.js. Executing a manipulation can lead to path traversal.
The identification of this vulnerability is CVE-2026-30973. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.