← Back to CVE search

CVE-2026-39243

decompress

Description

decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === -link-), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file-s content. Hardlinks are limited to files on the same filesystem and cannot target directories.

CVSS 5.5EPSS 0.328%Risk 0.57
View source
Published
2026-07-09 22:17:04
Affected versions
<4.2.2
Type
Library
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N