Description
decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to file entries, not symlink creation. An attacker can craft an archive with symlink entries pointing to sensitive files outside the extraction directory (e.g., /etc/passwd), enabling information disclosure when the application reads the extracted contents.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The decompress library, when running a version older than 4.2.2, accepts archive entries that are marked as symlinks and passes the link target retrieved from the archive unchanged to the Node.js fs.symlink() function. This behaviour allows an attacker to craft an archive containing a symlink pointing to arbitrary files outside the intended extraction directory, such as /etc/passwd or other sensitive configuration files. When the application later reads the contents of the extracted files, the symlink is resolved and the attacker can read data that the application was not intended to expose. The weakness maps to directory or path traversal style flaws (CWE-59, CWE-61) that lead to unintended information disclosure.

Affected Systems

Any Node.js application that incorporates the decompress npm module with a version lower than 4.2.2 for processing ZIP, TAR, or other archive formats is affected. Common contexts include web services that accept file uploads, continuous‑integration pipelines that import artifacts, or content import utilities that use decompress to extract user‑supplied archives. The issue is also recorded in the CPE database as redhat:hummingbird 1, indicating responsibility from RedHat’s Hummingbird initiative. The specific contexts mentioned are inferred from the description and are not explicitly provided in the input.

Risk and Exploitability

The CVSS score of 7.5 classifies this flaw as high risk when present. The EPSS score of less than 1% indicates a very low probability of public exploitation at the time of analysis, and the vulnerability is not included in the CISA KEV catalog. An attacker can exploit the flaw by delivering a malicious archive that contains a crafted symlink entry; no additional privileges or post‑exploit steps are required. If the application reads or processes the extracted files, the attacker can read files outside the extraction directory, leading to information disclosure.

Generated by OpenCVE AI on July 28, 2026 at 09:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade decompress to version 4.2.2 or later, where symlink targets are validated against the extraction root.
  • Configure the extraction process to use a dedicated temporary directory and explicitly reject any symlink that resolves to a location outside that directory.
  • Pre‑process archive entries to filter or sanitize symlink targets before invoking fs.symlink(), ensuring that only links pointing inside the intended extraction path are created.

Generated by OpenCVE AI on July 28, 2026 at 09:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title decompress: decompress: arbitrary symlink creation during archive extraction leads to information disclosure
First Time appeared Redhat
Redhat hummingbird
Weaknesses CWE-61
CPEs cpe:/a:redhat:hummingbird:1
Vendors & Products Redhat
Redhat hummingbird
References
Metrics threat_severity

None

threat_severity

Important


Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Symlink Creation Allows Sensitive File Disclosure in decompress NPM Package

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Symlink Creation Allows Sensitive File Disclosure in decompress NPM Package

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-59
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Kevva
Kevva decompress
Vendors & Products Kevva
Kevva decompress

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to file entries, not symlink creation. An attacker can craft an archive with symlink entries pointing to sensitive files outside the extraction directory (e.g., /etc/passwd), enabling information disclosure when the application reads the extracted contents.
References

Subscriptions

Kevva Decompress
Redhat Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T17:27:46.481Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39246

cve-icon Vulnrichment

Updated: 2026-07-10T17:10:18.349Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-09T00:00:00Z

Links: CVE-2026-39246 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')

  • CWE-61

    UNIX Symbolic Link (Symlink) Following