CVE-2026-24842

EUVD-2026-4909
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
GitHub_MCNA
8.2 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
Affected Products (NVD)
VendorProductVersion
isaacstar
𝑥
< 7.5.7
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
node-tar
bookworm
6.1.13+~cs7.0.5-1
fixed
bullseye
6.0.5+ds1+~cs11.3.9-1+deb11u2
fixed
bullseye (security)
6.0.5+ds1+~cs11.3.9-1+deb11u2
fixed
forky
6.2.1+ds1+~cs6.1.13-7
fixed
sid
6.2.1+ds1+~cs6.1.13-7
fixed
trixie
6.2.1+~cs7.0.8-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tar
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
needs-triage
trusty
needs-triage
xenial
needs-triage