CVE-2026-24842: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in isaacs node-tar
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
AI Analysis
Technical Summary
node-tar, a Node.js module for handling TAR archives, contains a vulnerability in versions before 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This discrepancy allows crafted malicious TAR archives to bypass path traversal protections and create hardlinks to arbitrary files outside the intended extraction directory. This vulnerability can lead to unauthorized information disclosure or system compromise. The fix is included in node-tar version 7.5.7. Red Hat advisories confirm the vulnerability affects their products that use node-tar, and no suitable mitigation other than upgrading is currently available.
Potential Impact
An attacker can craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. This can result in unauthorized disclosure of sensitive information or further compromise of the affected system. The CVSS v3.1 score is 8.2 (high severity) with network attack vector, low complexity, no privileges required, user interaction required, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none.
Mitigation Recommendations
A fix is available in node-tar version 7.5.7. Users and vendors should upgrade to this version or later to remediate the vulnerability. Red Hat advisories indicate that no effective mitigation other than upgrading currently meets their criteria for ease of use and applicability. Therefore, upgrading to a fixed version is the recommended remediation.
CVE-2026-24842: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in isaacs node-tar
Description
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
CVSS v3.1
Score 8.2high
Affected software
isaacs
node-tar
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
node-tar, a Node.js module for handling TAR archives, contains a vulnerability in versions before 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This discrepancy allows crafted malicious TAR archives to bypass path traversal protections and create hardlinks to arbitrary files outside the intended extraction directory. This vulnerability can lead to unauthorized information disclosure or system compromise. The fix is included in node-tar version 7.5.7. Red Hat advisories confirm the vulnerability affects their products that use node-tar, and no suitable mitigation other than upgrading is currently available.
Potential Impact
An attacker can craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. This can result in unauthorized disclosure of sensitive information or further compromise of the affected system. The CVSS v3.1 score is 8.2 (high severity) with network attack vector, low complexity, no privileges required, user interaction required, and scope changed. Confidentiality impact is high, integrity impact is low, and availability impact is none.
Mitigation Recommendations
A fix is available in node-tar version 7.5.7. Users and vendors should upgrade to this version or later to remediate the vulnerability. Red Hat advisories indicate that no effective mitigation other than upgrading currently meets their criteria for ease of use and applicability. Therefore, upgrading to a fixed version is the recommended remediation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-01-27T14:51:03.059Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-24842","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18480","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:18868","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:2900","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:6192","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:5447","vendor":"Red Hat"}]
Threat ID: 697959ec4623b1157c540f5b
Added to database: 01/28/2026, 00:35:56 UTC
Last enriched: 08/13/2026, 16:31:36 UTC
Last updated: 09/10/2026, 22:12:39 UTC
Views: 912
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.