CVE-2026-53486 is a path-traversal and unsafe link-handling vulnerability in the Node.js decompress archive-extraction package. Versions before 10.2.1 and versions from 11.0.0 before 11.1.3 can extract crafted archive entries outside the designated output directory. The flaw results from creating hardlinks and symlinks without validating their targets, using a string-prefix comparison for path containment, and preserving setuid, setgid, and sticky permission bits on extracted files.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This standalone repository provides an operational Python 3 PoC for CVE-2026-101894, a symlink-chain archive extraction traversal affecting vulnerable Node.js @xhmikosr/decompress releases and the unmaintained decompress package. Its primary poc.py script builds a malicious TAR, runs a local Node.js lab, fingerprints target-relative package manifests and lockfiles, and can concurrently POST the TAR to a configurable list of generic upload/extraction endpoints. The supplied lab pins @xhmikosr/decompress 11.1.3 and lab/run_poc.js confirms whether the marker escaped lab/out into lab/pocbit_escape.txt. The evil.tar fixture contains chained symlink members and marker files. Two auxiliary Python scripts normalize FOFA JSON/CSV exports into deduplicated HTTP(S) target lists for bulk scanning. Remote 'exploited' results are heuristic: they reflect a 2xx upload response rather than verified archive extraction or file traversal.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An earlier vulnerability in the decompress archive-extraction path validation logic. The content identifies CVE-2026-101894 as a bypass of its lexical path-containment fix, but provides no further technical details about the earlier flaw.
A previously addressed vulnerability whose incomplete hardening was bypassed by CVE-2026-101894. No additional technical details are provided.
A critical archive extraction vulnerability in the decompress package for Node.js that allows crafted archives to create files or links outside the intended extraction directory, enabling out-of-directory read/write via path traversal, unsafe link handling, and improper file mode sanitization.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.