OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101894

CRITICAL · CVSS 9.1 EPSS 0.81% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The decompress package for Node.js is vulnerable to a symlink attack that allows an attacker to craft an archive with chained symlinks, potentially enabling unauthorized file access or modification outside the designated output directory. This can lead to the overwriting of critical startup scripts or configurations, resulting in remote code execution. Organizations using the unmaintained decompress package or versions prior to 10.2.2 and 11.1.4 should prioritize patching to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101894
Severity
CRITICAL
CVSS
9.1
EPSS
0.81%

Original NVD Description

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.