When extracting an untrusted archive with the default decompress(input, output) API, a crafted archive containing a chain of symlink entries can make a later entry resolve outside the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside output, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.
This is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.
Fixed in 11.1.4 (latest) and backported to 10.2.2 (release-v10 dist-tag). Upgrade to one of these.
The unmaintained upstream decompress package shares this flaw and will not be patched. Migrate to @xhmikosr/decompress@11.1.4 (or @10.2.2).
None. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.
{
"cwe_ids": [
"CWE-22",
"CWE-59"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T23:49:42Z",
"nvd_published_at": "2026-09-28T17:17:48Z",
"severity": "CRITICAL"
}