Skip to content
cyberMEDIUM2026-04-21 22:16 UTC

CVE-2026-40931 - Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

CVE ID :CVE-2026-40931 Published : April 21, 2026, 10:16 p.m. | 44 minutes ago Description :Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. T

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber