Vulnerability intelligence
CVE-2026-53486
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
CVSS Score
—
Critical
EPSS — Exploit Probability
0.6%
Riskier than 48% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
1 article across 1 outlet · first covered Jul 12, 2026 · latest Jul 12, 2026
Coverage timeline
-
Popular NPM Decompress Package Hit by Critical Path Traversal Flawsecurityonline.info · Jul 12, 2026