CVE-2026-24842
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
| CWE | CWE-22 CWE-59 |
| Vendor | isaacs |
| Product | node-tar |
| Published | Jan 28, 2026 |
| Last Updated | Jun 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for isaacs node-tar
Be the first to know when new high vulnerabilities affecting isaacs node-tar are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
Affected Versions
isaacs / node-tar
< 7.5.7
References
github.com: https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v github.com: https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46 access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-24842 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2433645 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24842.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:33371 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:18480 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:18868 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:2900 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:6192 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:5447