CVE-2026-24842
Last modified
CVE-2026-24842 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Isaacs | Tar | < 7.5.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-24842?
How severe is CVE-2026-24842?
How do I fix CVE-2026-24842?
Are you affected by CVE-2026-24842?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
