@xhmikosr/decompress: Path traversal via symlink chain
🔗 CVE IDs covered (1)
📋 Description
Impact
When extracting an untrusted archive with the default decompress(input, output) API, a crafted archive containing a chain of symlink entries can make a later entry resolve outside the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside output, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.
This is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.
Patches
Fixed in 11.1.4 (latest) and backported to 10.2.2 (release-v10 dist-tag). Upgrade to one of these.
The unmaintained upstream decompress package shares this flaw and will not be patched. Migrate to @xhmikosr/[email protected] (or @10.2.2).
Workarounds
None. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.
🎯 Affected products3
- npm/@xhmikosr/decompress:>= 11.0.0, <= 11.1.3
- npm/@xhmikosr/decompress:<= 10.2.1
- npm/decompress:<= 4.2.1
🔗 References (7)
- https://github.com/XhmikosR/decompress/security/advisories/GHSA-hrh2-vp3x-79xf
- https://nvd.nist.gov/vuln/detail/CVE-2026-101894
- https://github.com/XhmikosR/decompress/commit/5f4b2f64abb31bbaf1fef8975b595fd7df2558d8
- https://github.com/XhmikosR/decompress/commit/f6c88c668216d6a12c6cecf4fe0b6c70bf77050a
- https://github.com/XhmikosR/decompress/releases/tag/v10.2.2
- https://github.com/XhmikosR/decompress/releases/tag/v11.1.4
- https://github.com/advisories/GHSA-hrh2-vp3x-79xf