CVE-2026-29786: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in isaacs node-tar
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.
AI Analysis
Technical Summary
The node-tar package for Node.js versions before 7.5.10 contains a path traversal vulnerability where a specially crafted tar archive can cause the creation of a hardlink pointing outside the extraction directory. This is achieved by using a drive-relative link target such as 'C:../target.txt', enabling file overwrite outside the current working directory during normal tar extraction. This vulnerability is tracked as CVE-2026-29786 and has a CVSS 4.0 score of 8.2 (high severity). The issue was patched in node-tar version 7.5.10. Red Hat has published an advisory confirming the vulnerability and its remediation.
Potential Impact
Successful exploitation allows an attacker to overwrite arbitrary files outside the extraction directory by leveraging a path traversal via hardlink creation. This can lead to unauthorized file modification, potentially compromising system integrity or security depending on the files overwritten.
Mitigation Recommendations
Upgrade node-tar to version 7.5.10 or later, where this vulnerability has been patched. No additional mitigation is required if the upgrade is applied. Patch status is confirmed by the vendor advisory from Red Hat.
CVE-2026-29786: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in isaacs node-tar
Description
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.
CVSS v4.0
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The node-tar package for Node.js versions before 7.5.10 contains a path traversal vulnerability where a specially crafted tar archive can cause the creation of a hardlink pointing outside the extraction directory. This is achieved by using a drive-relative link target such as 'C:../target.txt', enabling file overwrite outside the current working directory during normal tar extraction. This vulnerability is tracked as CVE-2026-29786 and has a CVSS 4.0 score of 8.2 (high severity). The issue was patched in node-tar version 7.5.10. Red Hat has published an advisory confirming the vulnerability and its remediation.
Potential Impact
Successful exploitation allows an attacker to overwrite arbitrary files outside the extraction directory by leveraging a path traversal via hardlink creation. This can lead to unauthorized file modification, potentially compromising system integrity or security depending on the files overwritten.
Mitigation Recommendations
Upgrade node-tar to version 7.5.10 or later, where this vulnerability has been patched. No additional mitigation is required if the upgrade is applied. Patch status is confirmed by the vendor advisory from Red Hat.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-03-04T16:26:02.899Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-29786","vendor":"Red Hat"}]
Threat ID: 69ac4840c48b3f10ffa9ddda
Added to database: 03/07/2026, 15:46:08 UTC
Last enriched: 07/15/2026, 08:49:31 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 521
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.