VYPR

decompress

by XhmikosR

Source repositories

CVEs (2)

  • CVE-2026-101894CriSep 28, 2026
    risk 0.52cvss 9.1epss 0.01

    The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive…

  • CVE-2026-53486CriJul 14, 2026
    risk 0.52cvss 9.1epss 0.01

    The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because…