← Zurück zur CVE-Suche

CVE-2026-39243

decompress

Beschreibung

decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === -link-), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file-s content. Hardlinks are limited to files on the same filesystem and cannot target directories.

CVSS 5.5EPSS 0.328%Risiko 0.57
Quelle öffnen
Veröffentlicht
2026-07-09 22:17:04
Betroffene Versionen
<4.2.2
Typ
Bibliothek
Vektor
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N