Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the decompress package for Node.js, which handles archive extraction. This flaw could allow an attacker to gain unauthorized access to files or execute arbitrary code on systems processing specially crafted archives. The issue stems from how the package handles symlinks during decompression, potentially bypassing security checks.
- Archive decompression vulnerability exists.
- Can lead to unauthorized file access or code execution.
- Confirm relevance and exposure within your systems.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by providing a specially crafted archive. This archive, when processed by the decompress package, tricks the system into following a chain of symbolic links. This allows the attacker to write files outside the intended output directory, potentially overwriting critical system files and leading to remote code execution.
- Requires an archive with chained symlinks.
- Triggered by archive decompression and symlink resolution.
- Allows unauthorized file writes, leading to RCE.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, a crafted archive could lead to files outside the designated output directory being read or written. This could potentially impact system startup scripts or configuration files, leading to unauthorized remote code execution.
- System configuration and startup scripts.
- Archive extraction process bypasses security checks.
- Remote code execution on affected systems.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this vulnerability, as it impacts a Node.js library used for archive decompression. The first practical step is to identify all instances where the `decompress` package is in use, determine if these instances are business-critical or exposed externally, and then locate the accountable owner to plan remediation.
- Application owners should own the issue.
- Verify if the package is business-critical.
- Plan remediation based on risk exposure.