Bug 2498840 (CVE-2026-39246) - CVE-2026-39246 decompress: decompress: arbitrary symlink creation during archive extraction leads to information disclosure
Summary: CVE-2026-39246 decompress: decompress: arbitrary symlink creation during arch...
Keywords:
Status: NEW
Alias: CVE-2026-39246
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2499745 2499747
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-09 22:03 UTC by OSIDB Bzimport
Modified: 2026-07-14 10:54 UTC (History)
12 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-09 22:03:28 UTC
decompress before 4.2.2 allows arbitrary symlink creation during archive extraction. When processing symlink entries (type === 'symlink'), the x.linkname field from the archive is passed directly to fs.symlink() without validation (index.js line 121). The preventWritingThroughSymlink check on line 98 only applies to file entries, not symlink creation. An attacker can craft an archive with symlink entries pointing to sensitive files outside the extraction directory (e.g., /etc/passwd), enabling information disclosure when the application reads the extracted contents.


Note You need to log in before you can comment on or make changes to this bug.