CVE-2026-42497: CWE-59 Improper Link Resolution Before File Access ('Link Following') in BINGOS Archive::Tar
Archive::Tar versions before 3.08 for Perl contain a vulnerability where hardlinks in tar archives can be extracted to attacker-controlled paths outside the intended extraction directory. This occurs because the function handling special files does not validate linknames against absolute paths or directory traversal sequences. As a result, an attacker can create a hardlink that points to a victim file's inode, allowing modification of that file through the extracted name. Additionally, file metadata such as mode, owner, and timestamps are applied to the victim file during extraction.
AI Analysis
Technical Summary
CVE-2026-42497 is a vulnerability in BINGOS Archive::Tar affecting versions prior to 3.08. The issue arises in the _make_special_file() function, which passes the tar header's linkname directly to the link() system call without validating whether the linkname is an absolute path or contains '..' segments. This improper validation allows extraction of hardlinks to paths outside the extraction directory, effectively linking to victim files. Subsequent writes to the extracted file modify the victim file's contents, and the post-extraction chmod, chown, and utime operations apply changes to the victim file's inode. The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access) and CWE-732 (Incorrect Permission Assignment for Critical Resource).
Potential Impact
An attacker can craft a malicious tar archive that, when extracted by a vulnerable Archive::Tar version, creates hardlinks pointing to arbitrary files outside the extraction directory. This enables unauthorized modification of those victim files' contents and metadata, leading to integrity violations. The CVSS score of 7.5 (high) reflects the network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid extracting untrusted tar archives with vulnerable versions of Archive::Tar. Consider using alternative extraction tools that properly validate linknames or manually inspect archives before extraction.
CVE-2026-42497: CWE-59 Improper Link Resolution Before File Access ('Link Following') in BINGOS Archive::Tar
Description
Archive::Tar versions before 3.08 for Perl contain a vulnerability where hardlinks in tar archives can be extracted to attacker-controlled paths outside the intended extraction directory. This occurs because the function handling special files does not validate linknames against absolute paths or directory traversal sequences. As a result, an attacker can create a hardlink that points to a victim file's inode, allowing modification of that file through the extracted name. Additionally, file metadata such as mode, owner, and timestamps are applied to the victim file during extraction.
CVSS v3.1
Score 7.5high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-42497 is a vulnerability in BINGOS Archive::Tar affecting versions prior to 3.08. The issue arises in the _make_special_file() function, which passes the tar header's linkname directly to the link() system call without validating whether the linkname is an absolute path or contains '..' segments. This improper validation allows extraction of hardlinks to paths outside the extraction directory, effectively linking to victim files. Subsequent writes to the extracted file modify the victim file's contents, and the post-extraction chmod, chown, and utime operations apply changes to the victim file's inode. The vulnerability is classified under CWE-59 (Improper Link Resolution Before File Access) and CWE-732 (Incorrect Permission Assignment for Critical Resource).
Potential Impact
An attacker can craft a malicious tar archive that, when extracted by a vulnerable Archive::Tar version, creates hardlinks pointing to arbitrary files outside the extraction directory. This enables unauthorized modification of those victim files' contents and metadata, leading to integrity violations. The CVSS score of 7.5 (high) reflects the network attack vector, low attack complexity, no privileges required, no user interaction, and impact limited to integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid extracting untrusted tar archives with vulnerable versions of Archive::Tar. Consider using alternative extraction tools that properly validate linknames or manually inspect archives before extraction.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CPANSec
- Date Reserved
- 2026-04-27T18:34:48.417Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a14f66ba5ae1af1aa1760a1
Added to database: 05/26/2026, 01:24:59 UTC
Last enriched: 06/24/2026, 17:21:22 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 150
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.