Description
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
Published: 2026-09-28
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Path Traversal Outside Output Directory
Action: Immediate Patch
AI Analysis

Impact

The decompress module for Node.js performs archive extraction without fully preventing path traversal. Prior to versions 10.2.2 and 11.1.4, the default API uses a containment check that ignores symlink chains. An attacker can embed a chain of symbolic links inside an archive so that a later entry resolves to a location outside the extraction directory. The resulting read or write of files beyond the intended directory can expose configuration files or overwrite startup scripts, potentially enabling remote code execution.

Affected Systems

The issue affects the maintained XhmikosR decompress library in all releases before 10.2.2 and 11.1.4, as well as the separately maintained decompress package in versions up to 4.2.1.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.1, indicating a high severity impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attacks would likely target systems that run the Node.js application and provide crafted archives to the decompress API; the path traversal can occur during normal extraction routines, potentially giving a local attacker read/write access beyond the intended directory. If the application automates extraction of user-supplied archives, an adversary could supply a malicious archive to create or modify files outside the output directory, leading to escalation or remote code execution.

Generated by OpenCVE AI on September 28, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to decompress v10.2.2 or v11.1.4, which address the symlink chain oversight.
  • Remove or replace any usage of the unmaintained decompress package prior to v4.2.1.
  • If an upgrade is not feasible, implement strict path validation around extraction or switch to a vetted alternative library.
  • Limit the extraction directory to a dedicated, permission–restricted location to minimize impact of any remaining traversal errors.

Generated by OpenCVE AI on September 28, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Kevva
Kevva decompress
Xhmikosr
Xhmikosr decompress
Vendors & Products Kevva
Kevva decompress
Xhmikosr
Xhmikosr decompress
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
Title @xhmikosr/decompress: Path traversal via symlink chain
Weaknesses CWE-22
CWE-59
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Kevva Decompress
Xhmikosr Decompress
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-28T17:39:11.304Z

Reserved: 2026-09-28T15:55:37.906Z

Link: CVE-2026-101894

cve-icon Vulnrichment

Updated: 2026-09-28T17:39:03.127Z

cve-icon NVD

Status : Received

Published: 2026-09-28T17:17:48.830

Modified: 2026-09-28T18:17:17.730

Link: CVE-2026-101894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T18:30:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')