Junglewise Threat Intelligence

CVE-2026-39243: kevva decompress arbitrary hardlink creation in archive extraction

CVE-2026-39243 · Severity: medium · CVSS 5.5 · Published 2026-07-09

Technologies: Kevin Mårtensson Decompress. Vendors: Kevin Mårtensson.

Executive brief

The decompress package is a popular Node.js library for extracting compressed archives. When extracting a crafted malicious archive, an attacker can create hardlinks to arbitrary files on the same filesystem, allowing them to read sensitive files (secrets, configuration, private keys) or corrupt them through modification. This vulnerability affects applications that extract untrusted archives.

Technical details

The vulnerability is a path traversal / improper link resolution flaw in the decompress library's archive extraction logic. When processing hardlink entries (type === 'link'), the x.linkname field is passed directly to fs.link() without validating that the target is within the intended extraction directory (index.js line 113). An attacker can craft a tar/archive with a link entry whose linkname is an absolute path (e.g., '/tmp/secret.txt' or '/etc/passwd'). The fs.link() call then creates a hardlink inside the extraction directory pointing to the target file, sharing the same inode. This allows the attacker to read the target file's contents by reading the hardlink, or corrupt the original file by writing to the hardlink. Hardlinks are constrained to the same filesystem and cannot target directories. The attack requires an application to extract an untrusted archive and requires user interaction (triggering the extraction), but no authentication. A fix should validate and resolve the link target to ensure it stays within the extraction directory boundary.

Affected products

  • kevva decompress <= 4.2.1

Timeline

  • 2026-07-04: disclosed
  • 2026-07-10: advisory

References

Related threats