Unzip written in pure JavaScript. Extracts a zip into a directory. Available as a library or a command line program.
Uses the yauzl ZIP parser.
2.0.2 patches GHSA-x7jf-2287-qcpf / CVE-2026-56876. Prior versions followed symlink entries in a zip without validating the target, so a malicious archive could drop a symlink like innocent.txt -> ../../../../etc/passwd and any later read or write via the extracted symlink would escape the extraction directory. 2.0.2 refuses symlink entries whose targets are absolute or resolve outside opts.dir.
Make sure you have Node 10 or greater installed.
Get the library:
npm install extract-zip --save
Install the command line program:
npm install extract-zip -g
const extract = require('extract-zip')
async function main () {
try {
await extract(source, { dir: target })
console.log('Extraction complete')
} catch (err) {
// handle any errors
}
}dir(required) - the path to the directory where the extracted files are writtendefaultDirMode- integer - Directory Mode (permissions), defaults to0o755defaultFileMode- integer - File Mode (permissions), defaults to0o644onEntry- function - if present, will be called with(entry, zipfile), entry is every entry from the zip file forwarded from theentryevent from yauzl.zipfileis theyauzlinstance
Default modes are only used if no permissions are set in the zip file.
extract-zip foo.zip <targetDirectory>
If not specified, targetDirectory will default to process.cwd().
