← Πίσω στην αναζήτηση CVE

CVE-2026-40931

Compressing

Περιγραφή

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for the actual filesystem state. By exploiting this -Logical vs. Physical- divergence, an attacker can bypass the security check using a Directory Poisoning technique (pre-existing symbolic links). This vulnerability is fixed in 2.1.1 and 1.10.5.

CVSS 8.4EPSS 0.258%Κίνδυνος 0.86
Προβολή πηγής
Δημοσίευση
2026-04-21 22:16:19
Επηρεαζόμενες εκδόσεις
<2.1.1,<1.10.5
Τύπος
Package
Διάνυσμα
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H