HomeCVE-2026-24842

CVE-2026-24842

HIGH
8.2CVSS
Published: 2026-01-28
Updated: 2026-01-29
AI Analysis

Description

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
changed
Confidentiality
high
Integrity
low
Availability
none
Weaknesses
CWE-22CWE-59

Metadata

Primary Vendor
UNKNOWN
Published
1/28/2026
Last Modified
1/29/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

No affected products information available.

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2026-24842 | HIGH Severity | CVEDatabase.com | CVEDatabase.com