decompress
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting decompresspage 1 of 1
- CVE-2020-12265CRITICALCVSS 9.8EG 9.8✓ Fixed in 4.2.12020-04-26
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
- CVE-2026-53486CRITICALCVSS 9.1EG 9.12026-07-06
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write fi…
Check whether decompress is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for decompress CVEs against the assets you own.
Start Free Scan →