PT-2026-6213 · Unknown · Compressing

·

CVE-2026-24884

·

Published

2026-02-03

·

Updated

2026-06-02

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Compressing versions prior to 1.10.4 Compressing version 2.0.0
Description Compressing is a compression and decompression library for Node.js. The compressing.tar.uncompress() function extracts TAR archives and restores symbolic links without validating their targets. An attacker can embed symlinks that resolve outside the intended extraction directory, causing subsequent file entries to be written to arbitrary locations on the host file system. This can lead to the overwriting of sensitive files or the creation of new files in security-critical locations. In environments where extraction occurs with elevated privileges or targets executable paths, this may result in code execution, privilege escalation, data corruption, or denial of service.
Recommendations Update Compressing versions prior to 1.10.4 to version 1.10.4. Update Compressing version 2.0.0 to version 2.0.1.

Exploit

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24884
GHSA-CC8F-XG8V-72M3

Affected Products

Compressing