XhmikosR has 2 CVEs on record. 2 were published in the last 90 days. The median CVSS is 9.1 (critical), with 2 rated critical.
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 9.1
- Publish → KEV
- —
- Last 90 days
- 2 prev 0
2
Total CVEs
2
Critical
0
CISA KEV
0
Exploited
XhmikosR vulnerabilities
CVEs affecting XhmikosR, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-101894Critical· 9.1The decompress package for Node.js extracts archives
The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An att…
▾ MidnightXhmikosR · decompressvia NVD
CVE-2026-53486Critical· 9.1Decompress: Archive extraction can create files and links outside of the target directory
Decompress: Archive extraction can create files and links outside of the target directory
▾ Midnightxhmikosr · @xhmikosr/decompressEPSS 0.75%via GHSA