CVE-2026-101894

CVE-2026-101894 published: The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a c...

View full NVD advisory → ← Back to CVE watch