CVE-2026-53486
published 2026-07-14CVE-2026-53486: The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory…
PriorityP355critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.75%
53.4th percentile
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| decompress_project | decompress | — | — |
| decompress_project | decompress | 0 – 4.2.1 | — |
| rhacm2 | volsync-operator-bundle | — | — |
| rhacm2 | volsync-rhel9 | — | — |
| xhmikosr | decompress | < 10.2.1 | 10.2.1 |
| xhmikosr | decompress | — | — |
| xhmikosr | decompress | >= 0 < 10.2.1 | 10.2.1 |
| xhmikosr | decompress | >= 11.0.0 < 11.1.3 | 11.1.3 |
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
vendor_redhat·2026-07-14·CVSS 9.1
CVE-2026-53486 [CRITICAL] CWE-22 decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
A flaw was found in the decompress package for Node.js. A remote attacker can exploit this vulnerability by crafting a malicious archive. When the archive is extracted, it can create files and links outside the intended directory, leading to unauthorized reading or writing of files. This is due to improper handling of hardlink and symlink entries, insufficient path containment checks, and failure to remove setuid, setgid, or sticky bits from file modes. This can result in high confidentiality and integrity impacts.
Statement: Red Hat Build of Keycloak, Red Hat Advanced Cluster Management (VolSync), Red Hat Hardened Images (dotnet8.0), and the Fedora/EPEL yarnpkg packages bundle the orig
VulDB
XhmikosR decompress up to 10.2.0/11.1.2 Archive Extraction symlink
vuldb·2026-07-15·CVSS 9.1
CVE-2026-53486 [CRITICAL] XhmikosR decompress up to 10.2.0/11.1.2 Archive Extraction symlink
A vulnerability, which was classified as critical, has been found in XhmikosR decompress up to 10.2.0/11.1.2. This issue affects some unknown processing of the component Archive Extraction. The manipulation leads to symlink following.
This vulnerability is listed as CVE-2026-53486. The attack may be initiated remotely. There is no available exploit.
GHSA
Decompress: Archive extraction can create files and links outside of the target directory
ghsa·2026-07-06
CVE-2026-53486 [CRITICAL] CWE-22 Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
### Impact
When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the plugins option.
A link (hardlink) or symlink entry is created without checking where its target points. A hardlink can be aimed at any file the running process can read; that file then appears inside the output directory and its contents are exposed. A symlink can point outside the output directory and redirect a later write.
The path containment check used a string prefix comparison (`realPath.indexOf(o
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [fedora-all]
bugzilla·2026-07-15·CVSS 9.1
CVE-2026-53486 [CRITICAL] CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [fedora-all]
CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. T
Bugzilla
CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [epel-all]
bugzilla·2026-07-15·CVSS 9.1
CVE-2026-53486 [CRITICAL] CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [epel-all]
CVE-2026-53486 yarnpkg: Decompress: Arbitrary file read/write via crafted archive extraction [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. Thi
Bugzilla
CVE-2026-53486 decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
bugzilla·2026-07-14·CVSS 9.1
CVE-2026-53486 [CRITICAL] CVE-2026-53486 decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
CVE-2026-53486 decompress: @xhmikosr/decompress: Decompress: Arbitrary file read/write via crafted archive extraction
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
https://github.com/XhmikosR/decompress/commit/281cefa00cd4275c10479bc5f1abba6b14dee8bdhttps://github.com/XhmikosR/decompress/commit/60b5299402e72b0b53ca2e55222e9a1ccb44afaehttps://github.com/XhmikosR/decompress/commit/9fcda4b0a66ca22dc8d337f9b0e7c30293c5fb89https://github.com/XhmikosR/decompress/commit/aca5aac415dc04a6fae5200e51368cff436a09ddhttps://github.com/XhmikosR/decompress/releases/tag/v10.2.1https://github.com/XhmikosR/decompress/releases/tag/v11.1.3https://github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9
2026-07-14
Published