StackRadar

CVE-2026-101894

Critical

Advisory

Published 29 Sept 2026In the index since 30 Sept 2026
Severity
Critical
worst across findings
CVSS
9.1
base score, highest
EPSS
0.008
56th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 18,035 indexed, latest versions
Container images
20
deployed by those charts
Fix available
1 of 2
affected packages

@xhmikosr/decompress: Path traversal via symlink chain

Carried by container images the latest versions of 21 of 18,035 indexed charts deploy, on 20 images.

Affected packageAffected versionsFixed inImages
decompressnpm1.0.7, 3.0.0, 4.2.0, 4.2.1no fix listed18
@xhmikosr/decompressnpm10.0.110.2.22
OSV records
GHSA-hrh2-vp3x-79xf

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
hubotdecayofmind1.0.21 of 3See more

hubot decayofmind 1.0.2

1 of the 3 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
decayofmind/hubot:3.3.21e18e92fe694
decompress@1.0.7
no fix listed

Open the chart page →

2,704
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
decompress@4.2.1
no fix listed

Open the chart page →

3,448
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
decompress@4.2.1
no fix listed

Open the chart page →

4,985
activepiecesadnoctemVerified publisher0.7.01 of 1See more

activepieces adnoctem 0.7.0

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
activepieces/activepieces:0.92.1d22e3f36f78d
decompress@4.2.1
no fix listed

Open the chart page →

1,814
colosseumbook-k8sinfra-v21.0.182 of 5See more

colosseum book-k8sinfra-v2 1.0.18

2 of the 5 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
sysnet4admin/colosseum-cms:loge74b43c7f492
@xhmikosr/decompress@10.0.1
10.2.2
sysnet4admin/colosseum-prm:log5802bfcd7fed
@xhmikosr/decompress@10.0.1
10.2.2

Open the chart page →

30,121
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
decompress@3.0.0
no fix listed

Open the chart page →

4,630
hubotcloudnativeapp0.0.11 of 1See more

hubot cloudnativeapp 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
minddocdev/hubot:0.1.96c60b11a4fa7
decompress@1.0.7
no fix listed

Open the chart page →

2,775
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
decompress@4.2.1
no fix listed

Open the chart page →

26,551
testnet-faucetethereum-helm-chartsVerified publisher0.1.31 of 1See more

testnet-faucet ethereum-helm-charts 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
parithoshj/testnet-faucet:9859e0dcdca426fea6d
decompress@4.2.0
no fix listed

Open the chart page →

3,146
activepiecesfmjstudios0.2.31 of 1See more

activepieces fmjstudios 0.2.3

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
activepieces/activepieces:0.28.0a12efde0c535
decompress@4.2.1
no fix listed

Open the chart page →

3,854
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
decompress@4.2.1
no fix listed

Open the chart page →

10,605
Governify-Bluejaygovernify0.1.01 of 12See more

Governify-Bluejay governify 0.1.0

1 of the 12 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
decompress@4.2.1
no fix listed

Open the chart page →

24,074
Governify-Falcongovernify0.1.01 of 10See more

Governify-Falcon governify 0.1.0

1 of the 10 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
governify/assets-manager:v1.4.12987672448c7
decompress@4.2.1
no fix listed

Open the chart page →

26,252
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
decompress@4.2.1
no fix listed

Open the chart page →

4,558
juice-shopjuice-shop5.9.01 of 1See more

juice-shop juice-shop 5.9.0

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
bkimminich/juice-shop:v20.2.08739101ade29
decompress@4.2.1
no fix listed

Open the chart page →

2,011
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
decompress@4.2.1
no fix listed

Open the chart page →

4,069
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
decompress@4.2.1
no fix listed

Open the chart page →

4,464
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
decompress@4.2.1
no fix listed

Open the chart page →

3,867
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
decompress@4.2.1
no fix listed

Open the chart page →

6,171
cadencewener0.23.01 of 5See more

cadence wener 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
decompress@4.2.1
no fix listed

Open the chart page →

13,185
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2026-101894.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
decompress@4.2.1
no fix listed

Open the chart page →

13,185

Container images carrying it

20 by charts deploying them

A fixed version is listed for 1 of the 2 affected packages.

Container imageDigestPackageFixed inUsed by
governify/assets-manager:v1.4.12987672448c7
decompress@4.2.1
no fix listed
2
ubercadence/web:v3.29.58564a5b44a6d
decompress@4.2.1
no fix listed
2
activepieces/activepieces:0.28.0a12efde0c535
decompress@4.2.1
no fix listed
1
activepieces/activepieces:0.23.0c26188b44e62
decompress@4.2.1
no fix listed
1
activepieces/activepieces:0.92.1d22e3f36f78d
decompress@4.2.1
no fix listed
1
bkimminich/juice-shop:v20.2.08739101ade29
decompress@4.2.1
no fix listed
1
decayofmind/hubot:3.3.21e18e92fe694
decompress@1.0.7
no fix listed
1
konradkleine/docker-registry-frontend:v2181aad54ee64
decompress@3.0.0
no fix listed
1
library/ghost:6.37.01ef2e532ca4d
decompress@4.2.1
no fix listed
1
library/ghost:6.25.12654b1e90413
decompress@4.2.1
no fix listed
1
library/ghost:6.41.129773d6be407
decompress@4.2.1
no fix listed
1
library/ghost:4.37.0767230c0f263
decompress@4.2.1
no fix listed
1
library/ghost:6.39.0-alpine77196da4b0df
decompress@4.2.1
no fix listed
1
library/ghost:5.79.083f7bf209844
decompress@4.2.1
no fix listed
1
minddocdev/hubot:0.1.96c60b11a4fa7
decompress@1.0.7
no fix listed
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
decompress@4.2.1
no fix listed
1
parithoshj/testnet-faucet:9859e0dcdca426fea6d
decompress@4.2.0
no fix listed
1
sysnet4admin/colosseum-cms:loge74b43c7f492
@xhmikosr/decompress@10.0.1
10.2.2
1
sysnet4admin/colosseum-prm:log5802bfcd7fed
@xhmikosr/decompress@10.0.1
10.2.2
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
decompress@4.2.1
no fix listed
1

syft 1.42.1 · advisories as of 7 Oct 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.