CVE-2026-53486

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
Configurations

No configuration.

History

14 Jul 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-14 21:17

Updated : 2026-07-15 20:29


NVD link : CVE-2026-53486

Mitre link : CVE-2026-53486

CVE.ORG link : CVE-2026-53486


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-59

Improper Link Resolution Before File Access ('Link Following')

CWE-732

Incorrect Permission Assignment for Critical Resource