Skip to main content

CVE-2026-101894: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in XhmikosR decompress

0
Critical
VulnerabilityCVE-2026-101894cvecve-2026-101894cwe-22cwe-59
Published: 09/28/2026 (09/28/2026, 16:57:11 UTC)
Source: CVE Database V5
Vendor/Project: XhmikosR
Product: decompress

Description

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.

CVSS v3.1

Score 9.1critical

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Affected software

XhmikosR

decompress

Affected versions
<10.2.2>=11.0.0 <11.1.4

kevva

decompress

Affected versions
<=4.2.1
@xhmikosr/decompress
pkg:npm/@xhmikosr/decompress
Affected versions
<10.2.2>=11.0.0 <11.1.4

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/28/2026, 17:18:09 UTC

Technical Analysis

The decompress package for Node.js prior to versions 10.2.2 and 11.1.4 contains a path traversal vulnerability (CWE-22) due to insufficient checks on symlink chains during archive extraction. An attacker can craft an archive with chained symlink entries that resolve outside the designated output directory, allowing arbitrary file writes or reads outside the intended path. This can lead to overwriting critical files such as startup scripts or configuration files, which may result in remote code execution. The vulnerability affects the maintained @xhmikosr/decompress package before 10.2.2 and between 11.0.0 and before 11.1.4. The unmaintained decompress package remains vulnerable through version 4.2.1. This vulnerability is a bypass of the incomplete mitigation implemented for CVE-2026-53486.

Potential Impact

Successful exploitation allows an attacker to write or read files outside the intended extraction directory by exploiting symlink traversal in archive extraction. This can lead to overwriting critical system files such as startup scripts or configuration files, potentially enabling remote code execution. The CVSS score of 9.1 reflects the critical nature of this vulnerability with high confidentiality and integrity impact and no required privileges or user interaction.

Mitigation Recommendations

The vulnerability is fixed in the maintained @xhmikosr/decompress package in versions 10.2.2 and 11.1.4. Users should upgrade to these versions or later to remediate the issue. The unmaintained decompress package remains unpatched through version 4.2.1; users of this package should migrate to the maintained fork or apply alternative mitigations. No vendor advisory content contradicts these recommendations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-09-28T15:55:37.906Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aba9de2f7a7c54106f66c8b

Added to database: 09/28/2026, 17:03:30 UTC

Last enriched: 09/28/2026, 17:18:09 UTC

Last updated: 09/29/2026, 02:47:40 UTC

Views: 12

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses