CVE-2026-24842
HIGHisaacs/tar < 7.5.7 - Path Traversal via Hardlink Entry Mismatch
Title source: llmDescription
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
References (11)
Core 11
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v
Patch x_refsource_misc
https://github.com/isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:18480
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:18868
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:2900
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:33371
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:5447
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:6192
Vendor Advisory
https://access.redhat.com/security/cve/CVE-2026-24842
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2433645
Scores
CVSS v3
8.2
EPSS
0.0054
EPSS Percentile
42.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-22
CWE-59
Status
published
Products (3)
isaacs/node-tar
< 7.5.7
isaacs/tar
< 7.5.7
npm/tar
0 - 7.5.7npm
Published
Jan 28, 2026
Tracked Since
Feb 18, 2026