Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Umar0X

#30292of 57,638
9.1Total CVSS
Vulnerabilities · 1
PT-2026-99937
9.1
2026-09-28
Npm · @Xhmikosr/Decompress · CVE-2026-101894
**Name of the Vulnerable Software and Affected Versions** @xhmikosr/decompress versions prior to 10.2.2 @xhmikosr/decompress versions prior to 11.1.4 decompress versions prior to 4.2.2 **Description** The default `decompress(input, output)` API uses lexical containment checks that fail to account for the kernel following a planted symlink chain. A symlink is a special type of file that serves as a reference to another file or directory. An attacker can provide a crafted archive with chained symlink entries, causing a subsequent entry to resolve outside the intended output directory. This allows unauthorized reading or writing of files outside the output folder, which can lead to remote code execution if startup scripts or configuration files are overwritten. **Recommendations** Update @xhmikosr/decompress to version 10.2.2 or later. Update @xhmikosr/decompress to version 11.1.4 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.