CVE-2026-53486Patch

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created without checking where targets point, path containment used a string prefix comparison, and file modes failed to remove setuid, setgid, or sticky bits. This issue is fixed in @xhmikosr/decompress versions 10.2.1 and 11.1.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-59CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-07-12); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-07-07: 1Mentions · 2026-07-12: 2Mentions · 2026-07-16: 1Patch / Workaround · 2026-07-07: 1Patch / Workaround · 2026-07-12: 2Patch / Workaround · 2026-07-16: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-12: 2Technical Details · 2026-07-16: 107-0707-1207-16
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-071
Patch1
2026-07-122
Disclosure1Patch1
2026-07-161
Patch1
Full discourse4 posts
  • kokumօtօ@__kokumoto
    Disclosure

    npmパッケージのdecompressに重大(Critical)な脆弱性。CVE-2026-53486はCVSSスコア9.1の指定ディレクトリ外ファイル作成。ハードリンクやシンボリックリンクリンクの宛先を全く検証していないのが悪い。11.1.3で修正。 https://securityonline.info/decompress-npm-cve-2026-53486/

    Post summary

    The tweet announces a critical vulnerability (CVE‑2026‑53486) in the npm decompress package that allows out‑of‑directory file creation via unchecked hardlinks/symlinks; it is mitigated by updating to version 11.1.3.

    000641.1K
    7.7K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A decompress npm vulnerability (CVE-2026-53486, CVSS 9.1) lets crafted archives write files outside the target folder via path traversal. Patch now. #decompress #npm #CVE202653486 #PathTraversal #NodeJS #CyberSecurity http://securityonline.info/decompress-npm-cve-2026-53486/

    Post summary

    The tweet announces a path‑traversal flaw in the decompress npm package, provides a security link, notes that a patch is available, and summarizes the vulnerability’s technical aspects.

    01062947
    12.9K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-53486 - Critical path traversal in @xhmikosr/decompress for Node.js. CVSS 9.1. Crafted archives can read/write files outside target dir via symlinks and setuid bits. Update to 10.2.1 or 11.1.3 immediately. #CVEAlert #NodeJS #infosec #devsecops #devops #Developer https://www.valtersit.com/cve/CVE-2026-53486/

    Post summary

    The tweet highlights CVE-2026-53486, a critical path traversal flaw in Node.js's decompress library, noting a CVSS 9.1 score and urging users to patch to the latest releases immediately.

    0000041
    982 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - decompress Archive Extraction Escapes Target Directory (CVE-2026-53486) The Node.js decompress library writes archive entries without properly containing them. A crafted archive can read or write files outside the extraction directory across every format (tar, gz, bz2, zip, plugins). Hardlink/symlink entries aren't checked against their target, so a hardlink can expose any file the process can read and a symlink can redirect a later write outside the output dir. The containment check also used a string-prefix compare (indexOf), letting /srv/out escape into a sibling like /srv/out-old, and file modes kept setuid/setgid/sticky bits - dangerous when extraction runs as root in CI, containers, or install scripts. 👉Upgrade to @xhmikosr/decompress 10.2.1 or 11.1.3; migrate off the unmaintained upstream `decompress` (≤4.2.1, no fix).

    Post summary

    CVE-2026-53486 allows directory traversal during archive extraction in Node.js’s decompress library; the advisory recommends upgrading to a patched decompression library to mitigate the vulnerability.

    0000080
    243 followersView on X

Explore more