Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-39243

    decompress: Decompress: File disclosure and corruption via arbitrary hardlink creation

    Last Modified: Jul 25, 2026
    Published: Jul 09, 2026

    CVE-2026-39246

    decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to file entries, not symlink creation. An attacker can craft an archive with symlink entries pointing to sensitive files outside the extraction directory (e.g., /etc/passwd), enabling information disclosure when the application reads the extracted contents.

    Last Modified: Jul 14, 2026
    Published: Jul 09, 2026

    CVE-2026-39245

    Directory Traversal and Arbitrary File Write in decompress npm Package

    Last Modified: Jul 13, 2026
    Published: Jul 09, 2026

    CVE-2026-10732

    Symlink‑Based Zip Slip Leading to Arbitrary File Write in decompress

    Last Modified: Jun 05, 2026
    Published: Jun 05, 2026
    Items Per Page
    Kevva Vulnerabilities & Security CVEs | CVE-DB