Executive brief
The 'decompress' library, a popular tool for extracting archives in Node.js applications, contains a security flaw in how it handles symbolic links. An attacker can provide a specially crafted archive that, when extracted, creates links to sensitive files on the host system (such as configuration files or passwords). If the application later reads or displays these extracted files, it could inadvertently expose private system data to the attacker.
Technical details
The 'decompress' package fails to validate the target of symbolic link entries during archive extraction. While the library includes a 'preventWritingThroughSymlink' check, this validation is only applied to file entries and not to the creation of the symlinks themselves. In 'index.js', the 'x.linkname' field from the archive is passed directly to 'fs.symlink()' without ensuring the target resides within the intended destination directory. An attacker can exploit this by crafting an archive containing a symlink that points to sensitive system files (e.g., /etc/passwd); if the application subsequently reads the extracted content, it will follow the link and disclose the contents of the target file.
Affected products
- kevva decompress < 4.2.2
Timeline
- 2026-07-04: disclosed: Issue reported on GitHub by devploit
- 2026-07-09: advisory: CVE published by NVD