{"id":"CVE-2026-53486","aliases":["GHSA-mp2f-45pm-3cg9"],"title":"Decompress: Archive extraction can create files and links outside of the target directory","summary":"Decompress: Archive extraction can create files and links outside of the target directory","severity":"critical","cvss":9.1,"cwe":["CWE-22","CWE-59","CWE-732"],"vendor":"xhmikosr","product":"@xhmikosr/decompress","ecosystem":"npm","affected":["@xhmikosr/decompress < 10.2.1","@xhmikosr/decompress >= 11.0.0, < 11.1.3","decompress <= 4.2.1"],"patched":["@xhmikosr/decompress 10.2.1","@xhmikosr/decompress 11.1.3"],"published":"2026-07-06","updated":"2026-07-06","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-mp2f-45pm-3cg9","references":[{"url":"https://github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9"},{"url":"https://github.com/XhmikosR/decompress/commit/281cefa"},{"url":"https://github.com/XhmikosR/decompress/commit/60b5299"},{"url":"https://github.com/XhmikosR/decompress/commit/aca5aac"},{"url":"https://github.com/advisories/GHSA-mp2f-45pm-3cg9"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-06T20:46:12.657Z","epss":0.00749,"epssPercentile":0.53442,"slug":"CVE-2026-53486","body":"## Overview\n\n### Impact\n\nWhen extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the plugins option.\n\nA link (hardlink) or symlink entry is created without checking where its target points. A hardlink can be aimed at any file the running process can read; that file then appears inside the output directory and its contents are exposed. A symlink can point outside the output directory and redirect a later write.\n\nThe path containment check used a string prefix comparison (`realPath.indexOf(outputPath) !== 0`). Output `/srv/out` does not contain `/srv/out-old`, but the prefix comparison treats it as inside, so an entry can escape into a sibling directory whose name starts with the output directory name.\n\nFile modes were applied as `mode & ~umask`, which does not remove the setuid, setgid, or sticky bits. A crafted entry can create a setuid or setgid file. This matters when extraction runs as root, for example in CI, containers, or install scripts.\n\nAny code that extracts archives from an untrusted or attacker-influenced source is affected. Archives are commonly downloaded before extraction, so this is reachable over the network in many setups.\n\n### Patches\n\nFixed in `@xhmikosr/decompress` 10.2.1 and 11.1.3. Link targets are now resolved and checked against the output directory, containment uses `path.relative`, and setuid, setgid, and sticky bits are removed.\n\nThe upstream `decompress` package is unmaintained, and all versions through its last release (4.2.1) have the same flaws. There is no upstream fix. Migrate to `@xhmikosr/decompress` 11.1.3 or later.\n\n### Workarounds\n\nExtract only archives you trust. Run extraction as a non-root user so the mode issue cannot create a privileged file. After extracting, reject any symlink or hardlink that points outside the target and any file with unexpected mode bits.\n\n### Resources\n\n* Related prior issue in the upstream project this package forks: CVE-2020-12265 / GHSA-qgfr-5hqp-vrw9\n* Fix commits and releases:\n  * https://github.com/XhmikosR/decompress/releases/tag/v10.2.1\n  * https://github.com/XhmikosR/decompress/releases/tag/v11.1.3\n  * https://github.com/XhmikosR/decompress/commit/aca5aac\n  * https://github.com/XhmikosR/decompress/commit/281cefa\n  * https://github.com/XhmikosR/decompress/commit/60b5299\n\n## Affected packages\n\n- `@xhmikosr/decompress < 10.2.1`\n- `@xhmikosr/decompress >= 11.0.0, < 11.1.3`\n- `decompress <= 4.2.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@xhmikosr/decompress 10.2.1`\n- `@xhmikosr/decompress 11.1.3`","depth":"midnight","depthScore":50,"depthScoreParts":{"impact":50.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}