CVE-2026-101894: Arbitrary File Read/Write via Symbolic Link Chaining in @xhmikosr/decompress
Vulnerability ID: CVE-2026-101894
CVSS Score: 9.1
Published: 2026-09-29
CVE-2026-101894 is a critical path traversal vulnerability in @xhmikosr/decompress before versions 10.2.2 and 11.1.4, stemming from an incomplete hardening bypass of CVE-2026-53486 where static lexical containment checks fail to detect kernel-level resolution of crafted symlink chains, allowing arbitrary local file modification and execution.
TL;DR
A path traversal vulnerability in @xhmikosr/decompress allows attackers to write files outside the target directory via a crafted chain of symlink entries, bypassing lexical containment checks.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-22
- Attack Vector: Network
- CVSS Score: 9.1
- EPSS Score: 0.00814
- Exploit Status: PoC
- KEV Status: Not Listed
Affected Systems
- @xhmikosr/decompress
- decompress
-
@xhmikosr/decompress: < 10.2.2 (Fixed in:
10.2.2) -
@xhmikosr/decompress: < 11.1.4 (Fixed in:
11.1.4) -
decompress: <= 4.2.1 (Fixed in:
None)
Code Analysis
Commit: 5f4b2f6
Implement physical validation of symbolic links
Commit: f6c88c6
Ensure symlinks resolve inside output using realpath
Commit: d761266
Open files with O_NOFOLLOW to mitigate TOCTOU symlink races
Commit: 9651c32
Refuse to extract an archive with duplicate entry paths
Exploit Details
- GitHub: Public PoC GitHub Repository
- External Analysis: External Exploit Analysis Article
Mitigation Strategies
- Upgrade @xhmikosr/decompress to fixed versions
- Replace legacy 'decompress' library with maintained fork
- Run extraction processes in isolated, non-root sandbox environments
Remediation Steps:
- Identify vulnerable packages using npm audit
- Update package.json dependencies to >=10.2.2 or >=11.1.4
- Replace any occurrences of 'decompress' with '@xhmikosr/decompress'
- Rebuild lockfiles and deploy patches
References
- Official Security Advisory
- NVD Vulnerability Detail
- CVE.org Authority Record
- Release Version 10.2.2
- Release Version 11.1.4
Read the full report for CVE-2026-101894 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)