DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-101894: CVE-2026-101894: Arbitrary File Read/Write via Symbolic Link Chaining in @xhmikosr/decompress

CVE-2026-101894: Arbitrary File Read/Write via Symbolic Link Chaining in @xhmikosr/decompress

Vulnerability ID: CVE-2026-101894
CVSS Score: 9.1
Published: 2026-09-29

CVE-2026-101894 is a critical path traversal vulnerability in @xhmikosr/decompress before versions 10.2.2 and 11.1.4, stemming from an incomplete hardening bypass of CVE-2026-53486 where static lexical containment checks fail to detect kernel-level resolution of crafted symlink chains, allowing arbitrary local file modification and execution.

TL;DR

A path traversal vulnerability in @xhmikosr/decompress allows attackers to write files outside the target directory via a crafted chain of symlink entries, bypassing lexical containment checks.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-22
  • Attack Vector: Network
  • CVSS Score: 9.1
  • EPSS Score: 0.00814
  • Exploit Status: PoC
  • KEV Status: Not Listed

Affected Systems

  • @xhmikosr/decompress
  • decompress
  • @xhmikosr/decompress: < 10.2.2 (Fixed in: 10.2.2)
  • @xhmikosr/decompress: < 11.1.4 (Fixed in: 11.1.4)
  • decompress: <= 4.2.1 (Fixed in: None)

Code Analysis

Commit: 5f4b2f6

Implement physical validation of symbolic links

Commit: f6c88c6

Ensure symlinks resolve inside output using realpath

Commit: d761266

Open files with O_NOFOLLOW to mitigate TOCTOU symlink races

Commit: 9651c32

Refuse to extract an archive with duplicate entry paths

Exploit Details

Mitigation Strategies

  • Upgrade @xhmikosr/decompress to fixed versions
  • Replace legacy 'decompress' library with maintained fork
  • Run extraction processes in isolated, non-root sandbox environments

Remediation Steps:

  1. Identify vulnerable packages using npm audit
  2. Update package.json dependencies to >=10.2.2 or >=11.1.4
  3. Replace any occurrences of 'decompress' with '@xhmikosr/decompress'
  4. Rebuild lockfiles and deploy patches

References


Read the full report for CVE-2026-101894 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)