Signal is active with 1 mentions in latest observed window
Immediate actions
Patch affected systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.
The tweet announces a critical vulnerability (CVE‑2026‑53486) in the npm decompress package that allows out‑of‑directory file creation via unchecked hardlinks/symlinks; it is mitigated by updating to version 11.1.3.
A decompress npm vulnerability (CVE-2026-53486, CVSS 9.1) lets crafted archives write files outside the target folder via path traversal. Patch now.
#decompress#npm#CVE202653486#PathTraversal#NodeJS#CyberSecurity
http://securityonline.info/decompress-npm-cve-2026-53486/
Post summary
The tweet announces a path‑traversal flaw in the decompress npm package, provides a security link, notes that a patch is available, and summarizes the vulnerability’s technical aspects.
#CVE-2026-53486 - Critical path traversal in @xhmikosr/decompress for Node.js. CVSS 9.1. Crafted archives can read/write files outside target dir via symlinks and setuid bits. Update to 10.2.1 or 11.1.3 immediately. #CVEAlert#NodeJS#infosec#devsecops#devops#Developer https://www.valtersit.com/cve/CVE-2026-53486/
Post summary
The tweet highlights CVE-2026-53486, a critical path traversal flaw in Node.js's decompress library, noting a CVSS 9.1 score and urging users to patch to the latest releases immediately.
🚨Critical - decompress Archive Extraction Escapes Target Directory (CVE-2026-53486)
The Node.js decompress library writes archive entries without properly containing them. A crafted archive can read or write files outside the extraction directory across every format (tar, gz, bz2, zip, plugins). Hardlink/symlink entries aren't checked against their target, so a hardlink can expose any file the process can read and a symlink can redirect a later write outside the output dir.
The containment check also used a string-prefix compare (indexOf), letting /srv/out escape into a sibling like /srv/out-old, and file modes kept setuid/setgid/sticky bits - dangerous when extraction runs as root in CI, containers, or install scripts.
👉Upgrade to @xhmikosr/decompress 10.2.1 or 11.1.3; migrate off the unmaintained upstream `decompress` (≤4.2.1, no fix).
Post summary
CVE-2026-53486 allows directory traversal during archive extraction in Node.js’s decompress library; the advisory recommends upgrading to a patched decompression library to mitigate the vulnerability.