← Blog · · df00tech

@xhmikosr/decompress: Symlink-Chain Path Traversal Bypasses Prior Archive Extraction Hardening

breaking ghsa npm CVE-2026-101894

What happened

A new advisory (GHSA-hrh2-vp3x-79xf, tracked as CVE-2026-101894, CVSS 9.1) reports a path traversal vulnerability in @xhmikosr/decompress. According to the advisory, when the default decompress(input, output) API extracts an untrusted archive, a crafted archive containing a chain of symlink entries can cause a later entry to resolve outside the intended output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a location outside output, allowing writes (and reads) outside the extraction directory. The advisory states this is a bypass of a previously fixed issue (GHSA-mp2f-45pm-3cg9) and that overwriting startup scripts or configuration files could lead to remote code execution. A public PoC is noted as available.

Why it matters

Any application that extracts attacker-controlled archives with @xhmikosr/decompress is potentially affected, per the advisory. The unmaintained upstream decompress package shares the same flaw and will not receive a fix, so consumers of either package should treat this as in scope. Because this is a bypass of an earlier hardening effort, environments that patched the original issue and assumed the extraction path was safe should re-verify their exposure.

What defenders should do now

  • Upgrade to @xhmikosr/[email protected] (latest) or 10.2.2 (release-v10 dist-tag), per the advisory's stated fix versions.
  • Migrate off the unmaintained decompress package entirely, since it will not be patched.
  • If you cannot upgrade immediately, the advisory states there is no workaround other than not extracting untrusted archives on affected versions; if extraction of untrusted input is unavoidable, validate each entry's resolved path out of band and reject any that escape the target directory, including via symlink resolution.
  • Inventory dependency trees (direct and transitive) for both @xhmikosr/decompress and decompress to identify exposure, and audit any code paths that extract archives sourced from users, uploads, or external feeds.
  • Consider sandboxing or containerizing archive extraction of untrusted input as a defense-in-depth measure, since symlink-based traversal techniques can be subtle to fully rule out with path checks alone.

Developing intel

This item is based on a same-day GHSA advisory published 2026-09-29; details may evolve as the maintainers, downstream consumers, and the community assess real-world exposure. For full technical detail, patch information, and updates, see the original advisory: GHSA-hrh2-vp3x-79xf.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.