← All CVEs

CVE-2026-53486

critical · 9.1

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.

9.1
CVSS
0.7%
EPSS (exploit prob.)
53rd
EPSS percentile
2026-07-14
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-22CWE-59CWE-732

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-53486