GHSA-hrh2-vp3x-79xf: Path Traversal

Published Sep 29, 2026
·
Updated

Impact

When extracting an untrusted archive with the default decompress(input, output) API, a crafted archive containing a chain of symlink entries can make a later entry resolve outside the output directory. The lexical containment checks pass, but the kernel follows the planted symlinks to a path outside output, letting an attacker write (and read) files outside the intended extraction directory. Overwriting startup scripts or configuration can lead to remote code execution.

This is a bypass of the hardening in GHSA-mp2f-45pm-3cg9. Any application that extracts attacker-controlled archives is affected.

Patches

Fixed in 11.1.4 (latest) and backported to 10.2.2 (release-v10 dist-tag). Upgrade to one of these.

The unmaintained upstream decompress package shares this flaw and will not be patched. Migrate to @xhmikosr/decompress@11.1.4 (or @10.2.2).

Workarounds

None. Do not extract untrusted archives on affected versions. If you cannot upgrade, validate entries out of band and reject any whose resolved path escapes the target directory.

Affected Software

3 affected componentsFixes available
npm/decompress<=4.2.1
npm/@xhmikosr/decompress<=10.2.1
10.2.2
npm/@xhmikosr/decompress>=11.0.0<=11.1.3
11.1.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@xhmikosr/decompress to a version that resolves this vulnerability.

    Fixed in 10.2.2
  2. Upgrade

    Upgrade npm/@xhmikosr/decompress to a version that resolves this vulnerability.

    Fixed in 11.1.4
  3. Upgrade

    Upgrade @xhmikosr/decompress to a version that resolves this vulnerability.

    Fixed in 11.1.4
  4. Upgrade

    Upgrade @xhmikosr/decompress to a version that resolves this vulnerability.

    Fixed in 10.2.2
  5. Compensating control

    Do not extract untrusted archives on affected versions.

  6. Compensating control

    If upgrading is not possible, validate archive entries out of band and reject any entry whose resolved path escapes the target directory.

Event History

Sep 29, 2026
Advisory Published
via GitHub·11:49 PM
Data Sourced
via GitHub·11:49 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which deployments are exposed?

Any application that extracts attacker-controlled archives using the default decompress(input, output) API is affected. The issue applies to npm/@xhmikosr/decompress before 11.1.4 or the 10.x release line before 10.2.2, as well as the unmaintained npm/decompress package.

2

What does an attacker need to exploit this?

An attacker needs to provide a crafted archive for the application to extract. The archive uses a chain of symlink entries so that a later extracted entry resolves outside the intended output directory; no privileges or user interaction are required.

3

Are default extraction settings affected?

Yes. The vulnerable behavior occurs with the default decompress(input, output) API because its lexical containment checks can be bypassed when the operating system follows symlinks created by earlier archive entries.

4

What can be done if an immediate upgrade is not possible?

There is no complete workaround. Do not extract untrusted archives on affected versions; if extraction cannot be avoided, validate archive entries out of band and reject entries whose resolved paths escape the target directory.

5

Which upgrade paths address the issue?

Upgrade to @xhmikosr/decompress 11.1.4 or later, or to 10.2.2 or later on the 10.x release-v10 line. The upstream decompress package is unmaintained and will not receive a patch, so migrate to @xhmikosr/decompress.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203