CVE-2026-101894
Received Received - Intake

Symlink Chain Bypass in Node.js Decompress Package

Vulnerability report for CVE-2026-101894, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: GitHub, Inc.

Description

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
xhmikosr decompress to 10.2.2 (inc)
xhmikosr decompress to 11.1.4 (inc)
xhmikosr decompress 10.2.2
xhmikosr decompress 11.1.4
xhmikosr decompress From 10.2.1 (inc) to 10.2.2 (exc)
xhmikosr decompress From 11.0.0 (inc) to 11.1.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-101894 is a critical path traversal vulnerability in the npm package @xhmikosr/decompress affecting versions between 11.0.0 and 11.1.3 and versions 10.2.1 and earlier. It allows attackers to extract malicious archives containing chained symlinks that bypass lexical containment checks, causing files to be written outside the intended output directory during extraction. This can lead to overwriting critical files like startup scripts or configuration files, potentially resulting in remote code execution.

Detection Guidance

Detecting this vulnerability requires checking if the affected versions of the decompress package are installed. Use commands like 'npm list @xhmikosr/decompress' or 'npm list decompress' to check installed versions. If versions between 10.2.1 and earlier or 11.0.0 to 11.1.3 are found, the system is vulnerable.

Impact Analysis

This vulnerability can allow attackers to read or write files outside the intended output directory when extracting archives. This may lead to overwriting startup scripts or configuration files, which can result in remote code execution. Attackers could gain unauthorized access to sensitive data or execute arbitrary code on the affected system.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive files, which may violate data protection requirements under GDPR (e.g., unauthorized access to personal data) and HIPAA (e.g., unauthorized access to protected health information). The ability to overwrite configuration files or execute remote code could result in data breaches or loss of confidentiality and integrity of regulated data.

Mitigation Strategies

Immediately upgrade to version 10.2.2 or 11.1.4 of @xhmikosr/decompress. If using the unmaintained 'decompress' package, consider replacing it or avoiding extraction of untrusted archives. Validate archive entries out-of-band before extraction.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101894. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart