CVE-2020-12265: Decompress Project Decompress
Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.
The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.
Affected products
- Decompress Project Decompress: before 4.2.1 (fixed in 4.2.1)
Published 2020-04-26. Last modified 2026-06-17.