Critical severity9.1NVD Advisory· Published Jul 14, 2026· Updated Jul 15, 2026
CVE-2026-53486
CVE-2026-53486
Description
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@xhmikosr/decompressnpm | < 10.2.1 | 10.2.1 |
@xhmikosr/decompressnpm | >= 11.0.0, < 11.1.3 | 11.1.3 |
decompressnpm | <= 4.2.1 | — |
Affected products
5- Range: <10.2.1 and <11.1.3
- osv-coords4 versionspkg:apk/chainguard/py3.10-captumpkg:apk/chainguard/py3.11-captumpkg:apk/chainguard/py3.12-captumpkg:apk/chainguard/py3.13-captum
< 0.9.0-r1+ 3 more
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
- (no CPE)range: < 0.9.0-r1
Patches
Vulnerability mechanics
References
11- github.com/advisories/GHSA-mp2f-45pm-3cg9ghsaADVISORY
- github.com/XhmikosR/decompress/commit/281cefaghsaWEB
- github.com/XhmikosR/decompress/commit/60b5299ghsaWEB
- github.com/XhmikosR/decompress/commit/aca5aacghsaWEB
- github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9nvdWEB
- github.com/XhmikosR/decompress/commit/281cefa00cd4275c10479bc5f1abba6b14dee8bdnvd
- github.com/XhmikosR/decompress/commit/60b5299402e72b0b53ca2e55222e9a1ccb44afaenvd
- github.com/XhmikosR/decompress/commit/9fcda4b0a66ca22dc8d337f9b0e7c30293c5fb89nvd
- github.com/XhmikosR/decompress/commit/aca5aac415dc04a6fae5200e51368cff436a09ddnvd
- github.com/XhmikosR/decompress/releases/tag/v10.2.1nvd
- github.com/XhmikosR/decompress/releases/tag/v11.1.3nvd
News mentions
0No linked articles in our index yet.