Node.js Decompress Package Vulnerability Allowing External File Access
CVE-2026-101894
What is CVE-2026-101894?
The decompress package for Node.js enables extraction of archives but contains a vulnerability in its default decompress(input, output) API. It fails to adequately check for symlink chains, allowing an attacker to craft malicious archives with chained symlink entries. This results in the potential for files outside of the intended output directory to be accessed or manipulated, creating risks such as overwriting critical startup scripts or configurations. These actions could lead to unauthorized remote code execution. The maintained @xhmikosr/decompress package has been updated to fix these issues in versions 10.2.2 and 11.1.4, while the unmaintained decompress package remains vulnerable.
Affected Version(s)
decompress < 10.2.2 < 10.2.2
decompress >= 11.0.0, < 11.1.4 < 11.0.0, 11.1.4
decompress <= 4.2.1
