[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-101894":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-28T18:04:36.952Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":220,"aliases":221,"duplicate_of":9,"upstream":222,"downstream":223,"duplicates":224,"related":225,"reserved_at":9,"published_at":226,"modified_at":227,"state":228,"summary":229,"references_raw":236,"kevs":260,"epss":9,"epss_history":261,"metrics":262,"affected":270},"CVE-2026-101894","The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code execution. The maintained @xhmikosr/decompress package is fixed in 10.2.2 and 11.1.4, but the separately affected unmaintained decompress package remains unpatched through 4.2.1. This vulnerability results from a bypass of the incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4.",null,[11,40],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],{"_key":41,"id":41,"name":42,"description":43,"type":15,"status":44,"abstraction":17,"likelihood_of_exploit":45,"capec":46},"CWE-59","Improper Link Resolution Before File Access ('Link Following')","The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.","Draft","Medium",[47,128,189,218],{"id":48,"name":49,"techniques":50},"CAPEC-132","Symlink Attack",[51],{"id":52,"name":53,"tactics":54,"countermeasures":61},"T1547.009","Shortcut Modification",[55,58],{"id":56,"name":57},"TA0110","Persistence",{"id":59,"name":60},"TA0111","Privilege Escalation",[62,67,72,76,80,84,89,94,98,102,107,111,115,119,123],{"id":63,"name":64,"tactic":65},"D3-LFP","Local File Permissions",{"name":66},"Isolate",{"id":68,"name":69,"tactic":70},"D3-DA","Dynamic Analysis",{"name":71},"Detect",{"id":73,"name":74,"tactic":75},"D3-FIM","File Integrity Monitoring",{"name":71},{"id":77,"name":78,"tactic":79},"D3-EFA","Emulated File Analysis",{"name":71},{"id":81,"name":82,"tactic":83},"D3-CM","Content Modification",{"name":66},{"id":85,"name":86,"tactic":87},"D3-FEV","File Eviction",{"name":88},"Evict",{"id":90,"name":91,"tactic":92},"D3-DF","Decoy File",{"name":93},"Deceive",{"id":95,"name":96,"tactic":97},"D3-FA","File Analysis",{"name":71},{"id":99,"name":100,"tactic":101},"D3-CF","Content Filtering",{"name":66},{"id":103,"name":104,"tactic":105},"D3-FE","File Encryption",{"name":106},"Harden",{"id":108,"name":109,"tactic":110},"D3-EAL","Executable Allowlisting",{"name":66},{"id":112,"name":113,"tactic":114},"D3-EDL","Executable Denylisting",{"name":66},{"id":116,"name":117,"tactic":118},"D3-RFAM","Remote File Access Mediation",{"name":66},{"id":120,"name":121,"tactic":122},"D3-CQ","Content Quarantine",{"name":66},{"id":124,"name":125,"tactic":126},"D3-RF","Restore File",{"name":127},"Restore",{"id":129,"name":130,"techniques":131},"CAPEC-17","Using Malicious Files",[132,169],{"id":133,"name":134,"tactics":135,"countermeasures":147},"T1574.005","Executable Installer File Permissions Weakness",[136,137,138,141,144],{"id":56,"name":57},{"id":59,"name":60},{"id":139,"name":140},"TA0030","Defense Evasion",{"id":142,"name":143},"TA0005","Stealth",{"id":145,"name":146},"TA0104","Execution",[148,152,156,161,165],{"id":149,"name":150,"tactic":151},"D3-SU","Software Update",{"name":106},{"id":153,"name":154,"tactic":155},"D3-RS","Restore Software",{"name":127},{"id":157,"name":158,"tactic":159},"D3-AVE","Asset Vulnerability Enumeration",{"name":160},"Model",{"id":162,"name":163,"tactic":164},"D3-SWI","Software Inventory",{"name":160},{"id":166,"name":167,"tactic":168},"D3-SBV","Service Binary Verification",{"name":71},{"id":170,"name":171,"tactics":172,"countermeasures":178},"T1574.010","Services File Permissions Weakness",[173,174,175,176,177],{"id":56,"name":57},{"id":59,"name":60},{"id":139,"name":140},{"id":142,"name":143},{"id":145,"name":146},[179,181,183,185,187],{"id":153,"name":154,"tactic":180},{"name":127},{"id":162,"name":163,"tactic":182},{"name":160},{"id":166,"name":167,"tactic":184},{"name":71},{"id":157,"name":158,"tactic":186},{"name":160},{"id":149,"name":150,"tactic":188},{"name":106},{"id":190,"name":191,"techniques":192},"CAPEC-35","Leverage Executable Code in Non-Executable Files",[193,200,207],{"id":194,"name":195,"tactics":196,"countermeasures":199},"T1027.006","HTML Smuggling",[197,198],{"id":139,"name":140},{"id":142,"name":143},[],{"id":201,"name":202,"tactics":203,"countermeasures":206},"T1027.009","Embedded Payloads",[204,205],{"id":139,"name":140},{"id":142,"name":143},[],{"id":208,"name":209,"tactics":210,"countermeasures":213},"T1564.009","Resource Forking",[211,212],{"id":139,"name":140},{"id":142,"name":143},[214],{"id":215,"name":216,"tactic":217},"D3-FFV","File Format Verification",{"name":66},{"id":29,"name":30,"techniques":219},[],[],[],[],[],[],[],"2026-09-28T16:57:11.440Z","2026-09-28T17:39:11.304Z","Received",{"cisa_kev":230,"cisa_ransomware":230,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":231,"severity_score":232,"severity_version":233,"severity_source":234,"severity_vector":235,"severity_status":228},false,"critical",9.1,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",[237,243,248,252,256],{"url":238,"sources":239,"tags":241},"https://github.com/XhmikosR/decompress/security/advisories/GHSA-hrh2-vp3x-79xf",[234,240],"nvd",[242],"X Refsource CONFIRM",{"url":244,"sources":245,"tags":246},"https://github.com/XhmikosR/decompress/commit/5f4b2f64abb31bbaf1fef8975b595fd7df2558d8",[234,240],[247],"X Refsource MISC",{"url":249,"sources":250,"tags":251},"https://github.com/XhmikosR/decompress/commit/f6c88c668216d6a12c6cecf4fe0b6c70bf77050a",[234,240],[247],{"url":253,"sources":254,"tags":255},"https://github.com/XhmikosR/decompress/releases/tag/v10.2.2",[234,240],[247],{"url":257,"sources":258,"tags":259},"https://github.com/XhmikosR/decompress/releases/tag/v11.1.4",[234,240],[247],[],[],[263,268],{"source":234,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":264,"cvss_v4_0":9},{"baseScore":232,"baseSeverity":265,"vectorString":235,"impactScore":266,"exploitabilityScore":267},"CRITICAL",8.7,10,{"source":240,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":269,"cvss_v4_0":9},{"baseScore":232,"baseSeverity":265,"vectorString":235,"impactScore":266,"exploitabilityScore":267},[271,281],{"ecosystem":9,"name":272,"vendor":273,"product":272,"cpe_part":274,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":275},"decompress","kevva","a",[276],{"version":277,"is_range":278,"range_type":234,"version_start":9,"version_start_type":9,"version_end":279,"version_end_type":280,"fixed_in":9},"\u003C= 4.2.1",true,"4.2.1","including",{"ecosystem":9,"name":272,"vendor":282,"product":272,"cpe_part":274,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":283},"xhmikosr",[284,288],{"version":285,"is_range":278,"range_type":234,"version_start":9,"version_start_type":9,"version_end":286,"version_end_type":287,"fixed_in":9},"\u003C 10.2.2","10.2.2","excluding",{"version":289,"is_range":278,"range_type":234,"version_start":290,"version_start_type":280,"version_end":291,"version_end_type":287,"fixed_in":9},">= 11.0.0, \u003C 11.1.4","11.0.0","11.1.4"]