@xhmikosr/decompress: Symlink-Chain Path Traversal Bypasses Prior Archive Extraction Hardening
What happened
A new advisory (GHSA-hrh2-vp3x-79xf, tracked as CVE-2026-101894, CVSS 9.1) reports a path traversal vulnerability in @xhmikosr/decompress. According to the advisory, when the default decompress(input, output) API extracts an untrusted archive, a crafted archive containing a chain of symlink entries can cause a later entry to resolve outside the intended output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a location outside output, allowing writes (and reads) outside the extraction directory. The advisory states this is a bypass of a previously fixed issue (GHSA-mp2f-45pm-3cg9) and that overwriting startup scripts or configuration files could lead to remote code execution. A public PoC is noted as available.
Why it matters
Any application that extracts attacker-controlled archives with @xhmikosr/decompress is potentially affected, per the advisory. The unmaintained upstream decompress package shares the same flaw and will not receive a fix, so consumers of either package should treat this as in scope. Because this is a bypass of an earlier hardening effort, environments that patched the original issue and assumed the extraction path was safe should re-verify their exposure.
What defenders should do now
- Upgrade to
@xhmikosr/[email protected](latest) or10.2.2(release-v10 dist-tag), per the advisory's stated fix versions. - Migrate off the unmaintained
decompresspackage entirely, since it will not be patched. - If you cannot upgrade immediately, the advisory states there is no workaround other than not extracting untrusted archives on affected versions; if extraction of untrusted input is unavoidable, validate each entry's resolved path out of band and reject any that escape the target directory, including via symlink resolution.
- Inventory dependency trees (direct and transitive) for both
@xhmikosr/decompressanddecompressto identify exposure, and audit any code paths that extract archives sourced from users, uploads, or external feeds. - Consider sandboxing or containerizing archive extraction of untrusted input as a defense-in-depth measure, since symlink-based traversal techniques can be subtle to fully rule out with path checks alone.
Developing intel
This item is based on a same-day GHSA advisory published 2026-09-29; details may evolve as the maintainers, downstream consumers, and the community assess real-world exposure. For full technical detail, patch information, and updates, see the original advisory: GHSA-hrh2-vp3x-79xf.