GHSA-hrh2-vp3x-79xfCriticalCVSS 9.1

@xhmikosr/decompress: Path traversal via symlink chain

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

When extracting an untrusted archive with the default decompress(input, output) API, a crafted archive containing a chain of symlink entries can make a later entry resolve outside the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside output, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.

This is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.

Patches

Fixed in 11.1.4 (latest) and backported to 10.2.2 (release-v10 dist-tag). Upgrade to one of these.

The unmaintained upstream decompress package shares this flaw and will not be patched. Migrate to @xhmikosr/[email protected] (or @10.2.2).

Workarounds

None. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.

🎯 Affected products3

  • npm/@xhmikosr/decompress:>= 11.0.0, <= 11.1.3
  • npm/@xhmikosr/decompress:<= 10.2.1
  • npm/decompress:<= 4.2.1

🔗 References (7)