Path Traversal Vulnerability in Decompress Package for Node.js by XhmikosR
CVE-2026-53486
9.1CRITICAL
What is CVE-2026-53486?
A vulnerability in the decompress package for Node.js allows crafted archives to extract files and links outside of the intended target directory. This security flaw arises from inadequate checks on hardlink and symlink entries, which can lead to unauthorized file access and manipulation. The exploitation risks include file reading and writing in unintended locations due to the absence of stringent path containment controls and failure to mitigate certain file modes. This issue has been addressed in decompress versions 10.2.1 and 11.1.3.
Affected Version(s)
decompress < 10.2.1 < 10.2.1
decompress >= 11.0.0, < 11.1.3 < 11.0.0, 11.1.3
