๐Ÿ” CVE Alert

CVE-2026-24842

HIGH 8.2

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

CWE CWE-22 CWE-59
Vendor isaacs
Product node-tar
Published Jan 28, 2026
Last Updated Jun 30, 2026
Stay Ahead of the Next One

Get instant alerts for isaacs node-tar

Be the first to know when new high vulnerabilities affecting isaacs node-tar are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

isaacs / node-tar
< 7.5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v github.com: https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-24842 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2433645 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24842.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33371 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:18480 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:18868 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2900 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6192 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:5447