PT-2026-99937 · Npm · @Xhmikosr/Decompress+1
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@xhmikosr/decompress versions prior to 10.2.2
@xhmikosr/decompress versions prior to 11.1.4
decompress versions prior to 4.2.2
Description
The default
decompress(input, output) API uses lexical containment checks that fail to account for the kernel following a planted symlink chain. A symlink is a special type of file that serves as a reference to another file or directory. An attacker can provide a crafted archive with chained symlink entries, causing a subsequent entry to resolve outside the intended output directory. This allows unauthorized reading or writing of files outside the output folder, which can lead to remote code execution if startup scripts or configuration files are overwritten.Recommendations
Update @xhmikosr/decompress to version 10.2.2 or later.
Update @xhmikosr/decompress to version 11.1.4 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Path traversal
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Xhmikosr/Decompress
Decompress