cbcvebase.
CVE-2026-53486
published 2026-07-14

CVE-2026-53486: The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory…

PriorityP355critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.75%
53.4th percentile
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.

Affected

8 ranges
VendorProductVersion rangeFixed in
decompress_projectdecompress——
decompress_projectdecompress0 – 4.2.1—
rhacm2volsync-operator-bundle——
rhacm2volsync-rhel9——
xhmikosrdecompress< 10.2.110.2.1
xhmikosrdecompress——
xhmikosrdecompress>= 0 < 10.2.110.2.1
xhmikosrdecompress>= 11.0.0 < 11.1.311.1.3

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.