CVE-2026-101894 is a path-traversal vulnerability in the default decompress(input, output) archive-extraction API of the Node.js @xhmikosr/decompress fork and the separate unmaintained decompress package. The affected implementation uses lexical containment checks that do not account for operating-system resolution of planted symbolic-link chains. A crafted archive can include chained symlink entries that cause a later entry to resolve outside the designated extraction directory. The flaw bypasses incomplete hardening for CVE-2026-53486. @xhmikosr/decompress is fixed in versions 10.2.2 and 11.1.4; the unmaintained decompress package remains unpatched through version 4.2.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This standalone repository provides an operational Python 3 PoC for CVE-2026-101894, a symlink-chain archive extraction traversal affecting vulnerable Node.js @xhmikosr/decompress releases and the unmaintained decompress package. Its primary poc.py script builds a malicious TAR, runs a local Node.js lab, fingerprints target-relative package manifests and lockfiles, and can concurrently POST the TAR to a configurable list of generic upload/extraction endpoints. The supplied lab pins @xhmikosr/decompress 11.1.3 and lab/run_poc.js confirms whether the marker escaped lab/out into lab/pocbit_escape.txt. The evil.tar fixture contains chained symlink members and marker files. Two auxiliary Python scripts normalize FOFA JSON/CSV exports into deduplicated HTTP(S) target lists for bulk scanning. Remote 'exploited' results are heuristic: they reflect a 2xx upload response rather than verified archive extraction or file traversal.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A symlink-chain path traversal vulnerability in @xhmikosr/decompress that lets crafted untrusted archives bypass lexical containment checks and read or write outside the intended extraction directory. Overwriting startup scripts or configuration files may result in remote code execution.
A critical symlink-chain path traversal vulnerability in the @xhmikosr/decompress Node.js archive-extraction library and its upstream decompress counterpart. Malicious ZIP or TAR archives can exploit nested self-referential symbolic links to bypass lexical path-containment checks and create or modify files outside the selected extraction directory.
A high-severity symlink-chain path traversal vulnerability in the Node.js decompress archive-extraction package. A crafted archive can cause later entries to resolve outside the intended output directory, enabling arbitrary external file reads or writes. Overwriting startup scripts or configuration may lead to remote code execution. It bypasses incomplete hardening for CVE-2026-53486.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.