CVE-2020-12265: Decompress Project Decompress

Critical severity, CVSS 9.8. EPSS: 2.1% chance of exploitation in the next 30 days.

The decompress package before 4.2.1 for Node.js is vulnerable to Arbitrary File Write via ../ in an archive member, when a symlink is used, because of Directory Traversal.

Affected products

Published 2020-04-26. Last modified 2026-06-17.