Xhmikosr Decompress vulnerabilities
2 known vulnerabilities affecting xhmikosr/decompress.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL2
Vulnerabilities
Page 1 of 1
CVE-2026-101894P2CRITICALCVSS 9.1fixed in 10.2.2v>= 11.0.0, < 11.1.42026-09-28
CVE-2026-101894 [CRITICAL] CWE-22 CVE-2026-101894: The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decomp
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside th
ghsanvd
CVE-2026-53486P3CRITICALCVSS 9.1fixed in 10.2.1v>= 11.0.0, < 11.1.32026-07-14
CVE-2026-53486 [CRITICAL] CWE-22 CVE-2026-53486: The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets poin
ghsanvd