Skip to content
Exploit for CVE-2026

Exploit for CVE-2026

Sploitus • September 29, 2026

Python 3 PoC for **[CVE-2026-101894]( — **Node.js** archive extraction in **`@xhmikosr/decompress`** (and unmaintained **`decompress`**) allows **read/write outside the output directory** via a **chain of symlink entries**. Bypass of **[CVE-2026-53486]( hardening. **CVSS 3.1 9.1 Critical**.

| **PoCbit** | |

| **Catalog** | |

| **Package** | `@xhmikosr/decompress` (maintained), `decompress` (kevva, **unpatched**) |

| **API** | Default `decompress(input, output)` |

| **CWE** | CWE-22 path traversal, CWE-59 link following |

| **Fixed** | **10.2.2** (10.x), **11.1.4** (11.x) |

| **GHSA** | [GHSA-hrh2-vp3x-79xf]( |

`decompress`, tar/zip vb. arşivleri hedef klasöre açarken lexical path kontrolleri uygular; ancak **ardışık symlink girdileri** ile kernel, sonraki girdileri **çıktı dizini dışında** çözebilir. Saldırgan kontrollü arşivle **config**, **startup script** veya hassas dosyaların **üzerine yazabilir** / okuyabilir → **RCE** senaryosu (CI, container, upload+extract servisleri).

**@xhmikosr/decompress** için yama: **10.2.2** ve **11.1.4**. Eski **`decompress`** paketi **4.2.1**’e kadar aynı sınıfta ve **yama almıyor** — `@xhmikosr/[email protected]+`’e geçin.

| **`--lab`** | `lab/` içinde **11.1.3** kurar, `evil.tar` symlink zinciri ile **dışarı yazmayı** doğrular |

| **`--write-evil-tar`** | Payload arşivini diske yazar (`POCBIT-101894-ESCAPED` marker) |

| **`check`** | Uzak hedefte `package.json` / lockfile → sürüm **≤ riskli** mi? |

| **`exploit`** | Symlink-chain **evil.tar** ile yaygın **upload** yollarına POST (mass bulk) |

| **mass** | `--list` + `-j`; `hits.txt` / **`exploited.txt`** |

Uzak exploit, sunucunun arşivi gerçekten **decompress ile açtığını** kanıtlamaz; **2xx upload kabulü** + zayıf sürüm fingerprint’i `exploited` sayılır. Kesin kanıt için **`--lab`**.

### `hits.txt` vs `exploited.txt` (sık görülen durum)

| **check → hits.txt** | `/package.json` veya `/package-lock.json` **açık** ve içinde **zayıf `decompress`** var |

| **exploit → exploited.txt** | PoC’nin denediği **genel upload URL’lerinden** en az biri **HTTP 2xx** döndü |

FOFA Express listesinde **500 scan → 2 hit** normaldir. **2 hit + 0 exploit** (`vulnerable_dep_no_upload_endpoint`) da normaldir: bağımlılık sızıntısı ≠ herkese açık arşiv upload. Bu CVE **istismar** için uygulamanın untrusted arşivi **`decompress()` ile açması** gerekir; HID / rastgele :8088 sitelerinde PoC’nin 8–11 varsayılan path’i çoğu zaman yoktur.

# Hit’ler: sadece bağımlılık + upload denemesi

python poc.py --list hits.txt --mode exploit -j 2

# Beklenen: upload_ok=0, status vulnerable_dep_no_upload_endpoint

| `@xhmikosr/decompress` **11.x** | 11.0.0 – **11.1.3** | **≥ 11.1.4** |

| `@xhmikosr/decompress` **10.x** | < **10.2.2** | **≥ 10.2.2** |

| `decompress` (kevva) | **≤ 4.2.1** | *none — migrate* |

**Lab:** Node.js + npm on PATH (Linux/macOS recommended for symlink extract behavior).

python poc.py -u --mode check

python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt

python poc.py -u --mode exploit --aggressive

python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload

| `--aggressive` | Exploit even without exposed vulnerable lockfile |

| `--upload-paths` | Custom comma-separated POST paths |

| `--exploited-list` | Targets where upload returned 2xx |

4. Regular files `…/pocbit_escape.txt` with marker payload

Matches the **symlink-chain bypass** class described in **11.1.4** release notes (realpath / containment fix).

FOFA JSON → python _format_fofa.py fofa_results_1000.json

→ fofa_results_1000.json (url), fofa_results_1000.csv, fofa_targets_1000.txt

python poc.py --list fofa_targets_1000.txt --mode check -j 40 → hits.txt

python poc.py --list fofa_results_1000.csv --mode check -j 40 # url column

python poc.py --list hits.txt --mode exploit -j 8 --aggressive → exploited.txt

Upload/zip FOFA dork listesi (`fofa_results_1000`) exploit yüzeyi için Express-only 500 listesinden daha uygundur; yine de **hit = lockfile + zayıf decompress**, exploit = upload 2xx.

body="\"decompress\"" && body="package-lock.json"

header="X-Powered-By: Express" && body="/package.json"

*(Lockfile rarely public in prod; check often finds staging, CI artifacts, misconfigured static hosting.)*

- [PoCbit CVE-2026-101894](

- [CVE.report](

- [v11.1.4 release](

- Prior: **CVE-2026-53486** / GHSA-mp2f-45pm-3cg9

Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.

CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit. CVSS 9.1.