{"id":"GHSA-mp2f-45pm-3cg9","summary":"Decompress: Archive extraction can create files and links outside of the target directory","details":"### Impact\n\nWhen extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the plugins option.\n\nA link (hardlink) or symlink entry is created without checking where its target points. A hardlink can be aimed at any file the running process can read; that file then appears inside the output directory and its contents are exposed. A symlink can point outside the output directory and redirect a later write.\n\nThe path containment check used a string prefix comparison (`realPath.indexOf(outputPath) !== 0`). Output `/srv/out` does not contain `/srv/out-old`, but the prefix comparison treats it as inside, so an entry can escape into a sibling directory whose name starts with the output directory name.\n\nFile modes were applied as `mode & ~umask`, which does not remove the setuid, setgid, or sticky bits. A crafted entry can create a setuid or setgid file. This matters when extraction runs as root, for example in CI, containers, or install scripts.\n\nAny code that extracts archives from an untrusted or attacker-influenced source is affected. Archives are commonly downloaded before extraction, so this is reachable over the network in many setups.\n\n### Patches\n\nFixed in `@xhmikosr/decompress` 10.2.1 and 11.1.3. Link targets are now resolved and checked against the output directory, containment uses `path.relative`, and setuid, setgid, and sticky bits are removed.\n\nThe upstream `decompress` package is unmaintained, and all versions through its last release (4.2.1) have the same flaws. There is no upstream fix. Migrate to `@xhmikosr/decompress` 11.1.3 or later.\n\n### Workarounds\n\nExtract only archives you trust. Run extraction as a non-root user so the mode issue cannot create a privileged file. After extracting, reject any symlink or hardlink that points outside the target and any file with unexpected mode bits.\n\n### Resources\n\n* Related prior issue in the upstream project this package forks: CVE-2020-12265 / GHSA-qgfr-5hqp-vrw9\n* Fix commits and releases:\n  * https://github.com/XhmikosR/decompress/releases/tag/v10.2.1\n  * https://github.com/XhmikosR/decompress/releases/tag/v11.1.3\n  * https://github.com/XhmikosR/decompress/commit/aca5aac\n  * https://github.com/XhmikosR/decompress/commit/281cefa\n  * https://github.com/XhmikosR/decompress/commit/60b5299","aliases":["CVE-2026-53486"],"modified":"2026-08-24T00:37:04.866102163Z","published":"2026-07-06T20:27:38Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-22","CWE-59","CWE-732"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-06T20:27:38Z"},"references":[{"type":"WEB","url":"https://github.com/XhmikosR/decompress/security/advisories/GHSA-mp2f-45pm-3cg9"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/commit/281cefa"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/commit/60b5299"},{"type":"WEB","url":"https://github.com/XhmikosR/decompress/commit/aca5aac"},{"type":"PACKAGE","url":"https://github.com/XhmikosR/decompress"}],"affected":[{"package":{"name":"@xhmikosr/decompress","ecosystem":"npm","purl":"pkg:npm/%40xhmikosr/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mp2f-45pm-3cg9/GHSA-mp2f-45pm-3cg9.json"}},{"package":{"name":"@xhmikosr/decompress","ecosystem":"npm","purl":"pkg:npm/%40xhmikosr/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.0"},{"fixed":"11.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mp2f-45pm-3cg9/GHSA-mp2f-45pm-3cg9.json"}},{"package":{"name":"decompress","ecosystem":"npm","purl":"pkg:npm/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"4.2.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-mp2f-45pm-3cg9/GHSA-mp2f-45pm-3cg9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}