Extracting archives made easy
decompress has critical vulnerabilities — do not use
Update to >= 11.1.3 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2026-10732 | decompress: Arbitrary File Write via Archive Extraction (Zip Slip) | — |
| critical | CVE-2026-53486 | Decompress: Archive extraction can create files and links outside of the target directory | 11.1.3 |
@types/decompress (DefinitelyTyped)Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/npm/decompressFirst published · 2013-08-23T15:15:31.955Z
Last updated · 2020-04-01T14:00:54.980Z