Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-101894: xhmikosr/decompress may write files outside target folder
CVE-2026-101894 · published 4 days ago
Summary
The decompress libraries for Node.js can be tricked by a specially crafted archive to place files outside the intended extraction folder. This could allow an attacker to modify scripts or configuration files on your system. Update to version 10.2.2 or later (or 11.1.4 for the newer line) and avoid using the unmaintained decompress package.
What to do
- Update xhmikosr decompress to version 11.1.4.
- Update xhmikosr decompress to version 10.2.2.
- Update xhmikosr @xhmikosr/decompress to version 11.1.4.
- Update xhmikosr @xhmikosr/decompress to version 10.2.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | xhmikosr | decompress | < 10.2.2 |
| – | kevva | decompress | <= 4.2.1 |
| npm | xhmikosr | decompress |
>= 11.0.0, <= 11.1.3 <= 10.2.1 Fix: upgrade to 11.1.4
|
| npm | – | decompress | <= 4.2.1 |
| npm | xhmikosr | @xhmikosr/decompress |
>= 11.0.0, < 11.1.4 < 10.2.2 Fix: upgrade to 11.1.4
|
Original advisory text
@xhmikosr/decompress: Path traversal via symlink chain
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
References
- https://github.com/XhmikosR/decompress/commit/5f4b2f64abb31bbaf1fef8975b595fd7df... Patch
- https://github.com/XhmikosR/decompress/commit/f6c88c668216d6a12c6cecf4fe0b6c70bf... Patch
- https://github.com/XhmikosR/decompress/security/advisories/GHSA-hrh2-vp3x-79xf Vendor Advisory
- https://github.com/advisories/GHSA-hrh2-vp3x-79xf
- https://github.com/XhmikosR/decompress/releases/tag/v10.2.2 URL
- https://github.com/XhmikosR/decompress/releases/tag/v11.1.4 URL
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-1018... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-101894 Vendor Advisory
- https://github.com/XhmikosR/decompress Product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-22Path Traversal
CWE-59Link Following
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101894 · NVD
CVE-2026-101894 · MITRE
GHSA-hrh2-vp3x-79xf · GHSA
CVE-2026-101894 · OSV
GHSA-hrh2-vp3x-79xf · OSV
Track software like this
Free during beta