Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-101894: xhmikosr/decompress may write files outside target folder

CVE-2026-101894 · published 4 days ago
Summary

The decompress libraries for Node.js can be tricked by a specially crafted archive to place files outside the intended extraction folder. This could allow an attacker to modify scripts or configuration files on your system. Update to version 10.2.2 or later (or 11.1.4 for the newer line) and avoid using the unmaintained decompress package.

What to do
  • Update xhmikosr decompress to version 11.1.4.
  • Update xhmikosr decompress to version 10.2.2.
  • Update xhmikosr @xhmikosr/decompress to version 11.1.4.
  • Update xhmikosr @xhmikosr/decompress to version 10.2.2.
Affected software
Ecosystem VendorProductAffected versions
– xhmikosr decompress < 10.2.2
– kevva decompress <= 4.2.1
npm xhmikosr decompress >= 11.0.0, <= 11.1.3
<= 10.2.1
Fix: upgrade to 11.1.4
npm – decompress <= 4.2.1
npm xhmikosr @xhmikosr/decompress >= 11.0.0, < 11.1.4
< 10.2.2
Fix: upgrade to 11.1.4
Original advisory text
@xhmikosr/decompress: Path traversal via symlink chain
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-22Path Traversal
CWE-59Link Following
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta