← Back to CVE search

CVE-2026-40931

Compressing

Description

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for the actual filesystem state. By exploiting this -Logical vs. Physical- divergence, an attacker can bypass the security check using a Directory Poisoning technique (pre-existing symbolic links). This vulnerability is fixed in 2.1.1 and 1.10.5.

CVSS 8.4EPSS 0.258%Risk 0.86
View source
Published
2026-04-21 22:16:19
Affected versions
<2.1.1,<1.10.5
Type
Package
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H