CVE-2026-24842

EUVD-2026-4909
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
isaacstar
𝑥
< 7.5.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-tar
bookworm
6.1.13+~cs7.0.5-1
fixed
bullseye
vulnerable
bullseye (security)
6.0.5+ds1+~cs11.3.9-1+deb11u3
fixed
forky
6.2.1+ds1+~cs6.1.13-10
fixed
sid
6.2.1+ds1+~cs6.1.13-10
fixed
trixie
6.2.1+~cs7.0.8-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tar
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
ignored
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
sgx-common
RHEL 9
0:2.26-7.el9
fixed
sgx-libs
RHEL 9
0:2.26-7.el9
fixed
sgx-mpa
RHEL 9
0:2.26-7.el9
fixed
sgx-pccs
RHEL 9
0:2.26-7.el9
fixed
sgx-pccs-admin
RHEL 9
0:2.26-7.el9
fixed
sgx-pckid-tool
RHEL 9
0:2.26-7.el9
fixed
tdx-qgs
RHEL 9
0:2.26-7.el9
fixed