Skip to main content
EPSS 0.5%top 56%

CVE-2026-24842: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in isaacs node-tar

0
High
VulnerabilityCVE-2026-24842cvecve-2026-24842cwe-22cwe-59gcve
Published: 01/28/2026 (01/28/2026, 00:20:13 UTC)
Source: CVE Database V5
Vendor/Project: isaacs
Product: node-tar

Description

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

CVSS v3.1

Score 8.2high

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Affected software

isaacs

node-tar

Affected versions
<7.5.7
node-tar
pkg:npm/node-tar
Affected versions
<7.5.7

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/13/2026, 16:31:36 UTC

Technical Analysis

node-tar, a Node.js module for handling TAR archives, contains a vulnerability in versions before 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This discrepancy allows crafted malicious TAR archives to bypass path traversal protections and create hardlinks to arbitrary files outside the intended extraction directory. This vulnerability can lead to unauthorized information disclosure or system compromise. The fix is included in node-tar version 7.5.7. Red Hat advisories confirm the vulnerability affects their products that use node-tar, and no suitable mitigation other than upgrading is currently available.

Potential Impact

An attacker can craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. This can result in unauthorized disclosure of sensitive information or further compromise of the affected system. The CVSS v3.1 score is 8.2 (high severity) with network attack vector, low complexity, no privileges required, user interaction required, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none.

Mitigation Recommendations

A fix is available in node-tar version 7.5.7. Users and vendors should upgrade to this version or later to remediate the vulnerability. Red Hat advisories indicate that no effective mitigation other than upgrading currently meets their criteria for ease of use and applicability. Therefore, upgrading to a fixed version is the recommended remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-01-27T14:51:03.059Z
Cvss Version
3.1
State
PUBLISHED
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-24842","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18480","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18868","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2900","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6192","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5447","vendor":"Red Hat"}]

Threat ID: 697959ec4623b1157c540f5b

Added to database: 01/28/2026, 00:35:56 UTC

Last enriched: 08/13/2026, 16:31:36 UTC

Last updated: 09/10/2026, 22:12:39 UTC

Views: 912

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses