External risk intelligence

Node.js Decompress Symlink Path Traversal Leading to RCE

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-101894

This is a vulnerability in a Node.js software library used for archive decompression. As a developer-focused utility library, it is typically used within build processes, data processing pipelines, or backend logic rather than acting as a public-facing network service or internet edge gateway.

Path Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the decompress package for Node.js, which handles archive extraction. This flaw could allow an attacker to gain unauthorized access to files or execute arbitrary code on systems processing specially crafted archives. The issue stems from how the package handles symlinks during decompression, potentially bypassing security checks.

  • Archive decompression vulnerability exists.
  • Can lead to unauthorized file access or code execution.
  • Confirm relevance and exposure within your systems.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by providing a specially crafted archive. This archive, when processed by the decompress package, tricks the system into following a chain of symbolic links. This allows the attacker to write files outside the intended output directory, potentially overwriting critical system files and leading to remote code execution.

  • Requires an archive with chained symlinks.
  • Triggered by archive decompression and symlink resolution.
  • Allows unauthorized file writes, leading to RCE.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, a crafted archive could lead to files outside the designated output directory being read or written. This could potentially impact system startup scripts or configuration files, leading to unauthorized remote code execution.

  • System configuration and startup scripts.
  • Archive extraction process bypasses security checks.
  • Remote code execution on affected systems.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are likely responsible for addressing this vulnerability, as it impacts a Node.js library used for archive decompression. The first practical step is to identify all instances where the `decompress` package is in use, determine if these instances are business-critical or exposed externally, and then locate the accountable owner to plan remediation.

  • Application owners should own the issue.
  • Verify if the package is business-critical.
  • Plan remediation based on risk exposure.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the decompress package for Node.js?

The decompress package is a utility library used by Node.js developers to automate the extraction of compressed archive files, such as .zip or .tar files. It is commonly integrated into backend software processes, automated build pipelines, and data processing workflows where handling uploaded or external archives is required.

What does CWE-22 and CWE-59 mean for CVE-2026-101894?

These codes identify Improper Limitation of a Pathname (CWE-22) and Improper Link Resolution (CWE-59). In plain terms, the software fails to verify that a file path is safe. Because it does not account for symbolic links—shortcuts to other files—it can be tricked into treating those shortcuts as actual files, allowing an attacker to escape the intended folder boundaries.

How is this vulnerability triggered?

An attacker must supply a specifically crafted archive file to the application. The vulnerability is triggered only when the library processes this archive and follows a chain of malicious symbolic links. Simply storing an archive without decompressing it does not trigger the bug; the system must actively execute the extraction logic using an affected version.

Is my system at risk if it is not internet-facing?

According to Halo Surface Signal, this library is typically used in backend or build logic rather than as a public-facing network service. While internet-facing applications are often higher priority, any system—internal or external—that automatically processes untrusted archive files uploaded by users or fetched from external sources remains a potential target.

Do I need to patch all instances of decompress?

Yes, you should identify all applications using the affected package. Prioritize updating the @xhmikosr/decompress version to 10.2.2 or 11.1.4. If you are using the unmaintained version of decompress, you should plan to migrate to a maintained alternative, as that branch remains unpatched and vulnerable.

References