PT-2026-99937 · Npm · @Xhmikosr/Decompress+1

·

CVE-2026-101894

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions @xhmikosr/decompress versions prior to 10.2.2 @xhmikosr/decompress versions prior to 11.1.4 decompress versions prior to 4.2.2
Description The default decompress(input, output) API uses lexical containment checks that fail to account for the kernel following a planted symlink chain. A symlink is a special type of file that serves as a reference to another file or directory. An attacker can provide a crafted archive with chained symlink entries, causing a subsequent entry to resolve outside the intended output directory. This allows unauthorized reading or writing of files outside the output folder, which can lead to remote code execution if startup scripts or configuration files are overwritten.
Recommendations Update @xhmikosr/decompress to version 10.2.2 or later. Update @xhmikosr/decompress to version 11.1.4 or later. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101894
GHSA-HRH2-VP3X-79XF

Affected Products

@Xhmikosr/Decompress
Decompress