Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 299 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.1) | 0.81% | — | Xhmikosr DecompressAI | 28/9/2026 | 30/9/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel following a planted symlink chain. An attacker can supply a crafted archive containing chained symlink entries so that a… | |
| Pendiente de análisis | Crítica (9.1) | 0.75% | — | Xhmikosr DecompressAI | 14/7/2026 | 15/7/2026 | The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an archive to a directory, a crafted archive can read or write files outside that directory because hardlink and symlink entries are created… | |
| Analizada | Alta (7.5) | 0.66% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to… | |
| Analizada | Media (6.2) | 0.38% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the extraction path validation (index.js line 106) use String.indexOf() to verify the resolved path is within the output directory:… | |
| Analizada | Media (5.5) | 0.30% | — | Decompress Project Decompress | 9/7/2026 | 13/7/2026 | decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === 'link'), the x.linkname field from the archive is passed directly to fs.link() without validation (index.js line 113). An attacker can… | |
| Pendiente de análisis | Media (5.6) | 0.52% | — | DecompressAI | 5/6/2026 | 7/9/2026 | All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written through the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Decompress Project Decompress | 26/4/2020 | 17/6/2026 | The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal. |