CVE-2026-101894 - @xhmikosr/decompress: Path traversal via symlink chain
CVE ID :CVE-2026-101894 Published : Sept. 28, 2026, 5:17 p.m. | 57 minutes ago Description :The decompress package for Node.js extracts archives. Prior to 10.2.2 and 11.1.4, the default decompress(input, output) API relies on lexical containment checks that do not account for the kernel...