GHSA-hrh2-vp3x-79xf

Suggest an improvement
Source
https://github.com/advisories/GHSA-hrh2-vp3x-79xf
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hrh2-vp3x-79xf
Aliases
Published
2026-09-29T23:49:42Z
Modified
2026-09-30T00:00:03Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
@xhmikosr/decompress: Path traversal via symlink chain
Details

Impact

When extracting an untrusted archive with the default decompress(input, output) API, a crafted archive containing a chain of symlink entries can make a later entry resolve outside the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside output, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.

This is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.

Patches

Fixed in 11.1.4 (latest) and backported to 10.2.2 (release-v10 dist-tag). Upgrade to one of these.

The unmaintained upstream decompress package shares this flaw and will not be patched. Migrate to @xhmikosr/decompress@11.1.4 (or @10.2.2).

Workarounds

None. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.

Database specific
{
    "cwe_ids":  [
        "CWE-22",
        "CWE-59"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-29T23:49:42Z",
    "nvd_published_at":  "2026-09-28T17:17:48Z",
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @xhmikosr/decompress

Package

Name
@xhmikosr/decompress
View open source insights on deps.dev
Purl
pkg:npm/%40xhmikosr/decompress

Affected ranges

Type
SEMVER
Events
Introduced
11.0.0
Fixed
11.1.4

Database specific

last_known_affected_version_range
"<= 11.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"

npm / @xhmikosr/decompress

Package

Name
@xhmikosr/decompress
View open source insights on deps.dev
Purl
pkg:npm/%40xhmikosr/decompress

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
10.2.2

Database specific

last_known_affected_version_range
"<= 10.2.1"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"

npm / decompress

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
4.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hrh2-vp3x-79xf/GHSA-hrh2-vp3x-79xf.json"