CVE-2026-24842

Published Jan 28, 2026

Last updated 3 months ago

CVSS high 8.2
Ubuntu
Splunk

Overview

Description
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Source
security-advisories@github.com
NVD status
Analyzed
Products
tar

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.2
Impact score
4.7
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-22

Social media

Hype score
Not currently trending

Configurations