CVE-2026-101894: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in XhmikosR decompress
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
AI Analysis
Technical Summary
The decompress package for Node.js prior to versions 10.2.2 and 11.1.4 contains a path traversal vulnerability (CWE-22) due to insufficient checks on symlink chains during archive extraction. An attacker can craft an archive with chained symlink entries that resolve outside the designated output directory, allowing arbitrary file writes or reads outside the intended path. This can lead to overwriting critical files such as startup scripts or configuration files, which may result in remote code execution. The vulnerability affects the maintained @xhmikosr/decompress package before 10.2.2 and between 11.0.0 and before 11.1.4. The unmaintained decompress package remains vulnerable through version 4.2.1. This vulnerability is a bypass of the incomplete mitigation implemented for CVE-2026-53486.
Potential Impact
Successful exploitation allows an attacker to write or read files outside the intended extraction directory by exploiting symlink traversal in archive extraction. This can lead to overwriting critical system files such as startup scripts or configuration files, potentially enabling remote code execution. The CVSS score of 9.1 reflects the critical nature of this vulnerability with high confidentiality and integrity impact and no required privileges or user interaction.
Mitigation Recommendations
The vulnerability is fixed in the maintained @xhmikosr/decompress package in versions 10.2.2 and 11.1.4. Users should upgrade to these versions or later to remediate the issue. The unmaintained decompress package remains unpatched through version 4.2.1; users of this package should migrate to the maintained fork or apply alternative mitigations. No vendor advisory content contradicts these recommendations.
CVE-2026-101894: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in XhmikosR decompress
Description
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.
CVSS v3.1
Score 9.1critical
Affected software
XhmikosR
decompress
kevva
decompress
pkg:npm/@xhmikosr/decompressRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The decompress package for Node.js prior to versions 10.2.2 and 11.1.4 contains a path traversal vulnerability (CWE-22) due to insufficient checks on symlink chains during archive extraction. An attacker can craft an archive with chained symlink entries that resolve outside the designated output directory, allowing arbitrary file writes or reads outside the intended path. This can lead to overwriting critical files such as startup scripts or configuration files, which may result in remote code execution. The vulnerability affects the maintained @xhmikosr/decompress package before 10.2.2 and between 11.0.0 and before 11.1.4. The unmaintained decompress package remains vulnerable through version 4.2.1. This vulnerability is a bypass of the incomplete mitigation implemented for CVE-2026-53486.
Potential Impact
Successful exploitation allows an attacker to write or read files outside the intended extraction directory by exploiting symlink traversal in archive extraction. This can lead to overwriting critical system files such as startup scripts or configuration files, potentially enabling remote code execution. The CVSS score of 9.1 reflects the critical nature of this vulnerability with high confidentiality and integrity impact and no required privileges or user interaction.
Mitigation Recommendations
The vulnerability is fixed in the maintained @xhmikosr/decompress package in versions 10.2.2 and 11.1.4. Users should upgrade to these versions or later to remediate the issue. The unmaintained decompress package remains unpatched through version 4.2.1; users of this package should migrate to the maintained fork or apply alternative mitigations. No vendor advisory content contradicts these recommendations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-09-28T15:55:37.906Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aba9de2f7a7c54106f66c8b
Added to database: 09/28/2026, 17:03:30 UTC
Last enriched: 09/28/2026, 17:18:09 UTC
Last updated: 09/29/2026, 02:47:40 UTC
Views: 12
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.