Node.js Decompress Package Vulnerability Allowing External File Access
CVE-2026-101894

9.1CRITICAL

Key Information:

Vendor

Xhmikosr

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101894?

The decompress package for Node.js enables extraction of archives but contains a vulnerability in its default decompress(input, output) API. It fails to adequately check for symlink chains, allowing an attacker to craft malicious archives with chained symlink entries. This results in the potential for files outside of the intended output directory to be accessed or manipulated, creating risks such as overwriting critical startup scripts or configurations. These actions could lead to unauthorized remote code execution. The maintained @xhmikosr/decompress package has been updated to fix these issues in versions 10.2.2 and 11.1.4, while the unmaintained decompress package remains vulnerable.

Affected Version(s)

decompress < 10.2.2 < 10.2.2

decompress >= 11.0.0, < 11.1.4 < 11.0.0, 11.1.4

decompress <= 4.2.1

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.