{"id":"GHSA-hrh2-vp3x-79xf","summary":"@xhmikosr/decompress: Path traversal via symlink chain","details":"### Impact\n\nWhen extracting an untrusted archive with the default `decompress(input, output)` API, a crafted archive containing a chain of symlink entries can make a later entry resolve **outside** the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside `output`, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.\n\nThis is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.\n\n### Patches\n\nFixed in **11.1.4** (`latest`) and backported to **10.2.2** (`release-v10` dist-tag). Upgrade to one of these.\n\nThe unmaintained upstream `decompress` package shares this flaw and will not be patched. Migrate to `@xhmikosr/decompress@11.1.4` (or `@10.2.2`).\n\n### Workarounds\n\nNone. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.","aliases":["CVE-2026-101894"],"modified":"2026-09-30T00:00:03.842182309Z","published":"2026-09-29T23:49:42Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-29T23:49:42Z","nvd_published_at":"2026-09-28T17:17:48Z","cwe_ids":["CWE-22","CWE-59"],"severity":"CRITICAL"},"references":[{"type":"WEB","url":"https://github.com/XhmikosR/decompress/security/advisories/GHSA-hrh2-vp3x-79xf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101894"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/commit/5f4b2f64abb31bbaf1fef8975b595fd7df2558d8"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/commit/f6c88c668216d6a12c6cecf4fe0b6c70bf77050a"},{"type":"PACKAGE","url":"https://github.com/XhmikosR/decompress"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/releases/tag/v10.2.2"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/releases/tag/v11.1.4"}],"affected":[{"package":{"name":"@xhmikosr/decompress","ecosystem":"npm","purl":"pkg:npm/%40xhmikosr/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.0"},{"fixed":"11.1.4"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.1.3","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"}},{"package":{"name":"@xhmikosr/decompress","ecosystem":"npm","purl":"pkg:npm/%40xhmikosr/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.2.2"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 10.2.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"}},{"package":{"name":"decompress","ecosystem":"npm","purl":"pkg:npm/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"4.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}