Impact
The decompress module for Node.js performs archive extraction without fully preventing path traversal. Prior to versions 10.2.2 and 11.1.4, the default API uses a containment check that ignores symlink chains. An attacker can embed a chain of symbolic links inside an archive so that a later entry resolves to a location outside the extraction directory. The resulting read or write of files beyond the intended directory can expose configuration files or overwrite startup scripts, potentially enabling remote code execution.
Affected Systems
The issue affects the maintained XhmikosR decompress library in all releases before 10.2.2 and 11.1.4, as well as the separately maintained decompress package in versions up to 4.2.1.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.1, indicating a high severity impact. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attacks would likely target systems that run the Node.js application and provide crafted archives to the decompress API; the path traversal can occur during normal extraction routines, potentially giving a local attacker read/write access beyond the intended directory. If the application automates extraction of user-supplied archives, an adversary could supply a malicious archive to create or modify files outside the output directory, leading to escalation or remote code execution.
OpenCVE Enrichment