Junglewise Threat Intelligence

CVE-2026-39245: kevva decompress directory traversal in path validation

CVE-2026-39245 · Severity: info · CVSS 9.8 · Published 2026-07-09

Technologies: Kevin Mårtensson Decompress. Vendors: Kevin Mårtensson.

Executive brief

The 'decompress' library, a popular tool for extracting archive files in Node.js applications, contains a security flaw in how it validates file paths. An attacker can provide a specially crafted archive that, when extracted, writes files to unintended locations on the server's disk. This could allow an attacker to overwrite critical system files or application configurations, potentially leading to full system compromise or data loss.

Technical details

The vulnerability exists in index.js within the safeMakeDir function and extraction path validation logic. The library uses String.indexOf() to verify if a resolved path is within the output directory but fails to enforce a path separator boundary. For example, a check for '/tmp/app' would incorrectly validate '/tmp/app_config' because the latter starts with the same string. When combined with unvalidated symlink creation, a remote attacker can bypass intended directory restrictions to perform arbitrary file writes. This is a bypass of the previous fix for CVE-2020-12265. The issue is resolved in version 4.2.2 by ensuring a path separator is appended during the containment check.

Affected products

  • kevva decompress < 4.2.2

Timeline

  • 2026-07-04: disclosed: Issue reported on GitHub by devploit
  • 2026-07-09: advisory: CVE-2026-39245 published

References

Related threats