CVE 8.4 HIGH

Compressing Vulnerable to Arbitrary File Write via Symlink Extraction_CVE-2026-24884

8.4 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validating their targets. By embedding symlinks that resolve outside the intended extraction directory, an attacker can cause subsequent file entries to be written to arbitrary locations on the host file system. Depending on the extractorโ€™s handling of existing files, this behavior may allow overwriting sensitive files or creating new files in security-critical locations. This issue has been patched in versions 1.10.4 and 2.0.1.

Basic Information

ID CVE-2026-24884
Source GitHub_M
Published Feb 4, 2026 at 19:35

Affected Product

Vendor node-modules
Product compressing
Version = 2.0.0
Affected Versions node-modules compressing = 2.0.0
node-modules compressing < 1.10.4

CWE Classification

References

๐Ÿ’ญ Join the Security Discussion

๐Ÿ”’ Your email address will not be published. Required fields are marked *

โš ๏ธ Please be respectful and constructive in your comments. Security discussions should remain professional.