Descrição
decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === -link-), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can craft an archive with a hardlink entry whose linkname is an absolute path to any file on the same filesystem. This creates a hardlink inside the extraction directory that shares the same inode as the target file, enabling both reading and overwriting the original file-s content. Hardlinks are limited to files on the same filesystem and cannot target directories.
CVSS 5.5EPSS 0.328%Risco 0.57
Ver fonte- Publicação
- 2026-07-09 22:17:04
- Versões afetadas
- <4.2.2
- Tipo
- Biblioteca
- Vetor
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N