4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether decompress is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CRITICAL 9.1
CVE-2026-53486
Decompress: Archive extraction can create files and links outside of the target directory
MEDIUM 5.5
CVE-2026-39243
decompress allows arbitrary hardlink creation during archive extraction
MEDIUM 6.4
CVE-2026-10732
decompress: Arbitrary File Write via Archive Extraction (Zip Slip)
CRITICAL 9.8
CVE-2020-12265
Path Traversal in decompress
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes