Vulnerabilities/

Decompress: Archive extraction can create files and links outside of the target directory

Severity:
High

Description

When extracting an archive to a directory, a crafted archive can read or write files outside that directory. The flaw is in the code that writes the parsed entries, so it affects every format decompress handles: tar, tar.gz, tar.bz2, and zip by default, plus any others added through the plugins option.

Recommendation

Update the @xhmikosr/decompress package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@xhmikosr/decompress
Anything's wrong? Let us know Last updated on July 06, 2026