Aller au contenu principal
CRITICAL

CVE-2026-101894

CVSS v3

9.1

CRITICAL

Score EPSS

—

probabilité d’exploitation

CISA KEV

Non

exploitation connue

Exploitation

—

statut SSVC

Description

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code exe

Détails techniques

Vecteur CVSS v3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Publiée le
2026-09-28
Dernière modification
2026-09-28

Questions fréquentes

Qu’est-ce que CVE-2026-101894 ?

The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a later entry resolves outside the output directory. This allows files outside output to be read or written, and overwriting startup scripts or configuration can lead to remote code exe

CVE-2026-101894 est-elle activement exploitée ?

Aucune exploitation active de CVE-2026-101894 n’est confirmée.

Quel est le score CVSS de CVE-2026-101894 ?

CVE-2026-101894 a un score de base CVSS v3 de 9.1 (gravité CRITICAL), avec le vecteur CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N.

CVE-2026-101894 touche-t-elle votre environnement ?

Utilisez isMalicious pour vérifier si l’une de vos IP ou l’un de vos domaines est associé aux IOC de cette vulnérabilité.

Sans carte bancaire · 500 vérifications gratuites par mois · Clé API gratuite