The Decompress Project maintains a focused decompression utility where observed vulnerabilities cluster around file-system access controls, specifically path traversal and improper link resolution during archive extraction. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Decompress Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-39246HIGH decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is | Jul 9, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-39245MEDIUM decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write. The safeMakeDir function (index.js line 29) and the e | Jul 9, 2026 | 6.2 | 30 | NO | NO |
CVE-2020-12265CRITICAL The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal. | Apr 26, 2020 | 9.8 | 30 | NO | NO |
CVE-2026-39243MEDIUM decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. When processing hardlink entries (type === | Jul 9, 2026 | 5.5 | 28 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Decompress Project.
Media articles that mention a CVE ID that affects a product developed by Decompress Project — matched by CVE ID, not by vendor name.