PT-2026-23608 · Node-Tar+2 · Node-Tar+2

·

CVE-2026-29786

·

Published

2026-03-05

·

Updated

2026-09-01

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions node-tar versions prior to 7.5.10
Description A flaw in the extraction logic allows an attacker to create a hardlink that points outside the intended extraction directory. By using a drive-relative link target, such as C:../target.txt, the software can be tricked into bypassing path restrictions. This occurs because the logic checks for .. segments before stripping absolute roots, allowing the linkpath to escape the current working directory (cwd) during the execution of the tar.x() function. This results in an arbitrary file overwrite primitive with the permissions of the process performing the extraction, which is particularly critical for services that unpack untrusted archives or build pipelines consuming third-party files.
Recommendations Update node-tar to version 7.5.10 or later.

Exploit

Fix

DoS

Path traversal

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-79553
AZL-79556
BDU:2026-06967
CLEANSTART-2026-AD27625
CLEANSTART-2026-CB77162
CLEANSTART-2026-CE10526
CLEANSTART-2026-DU32240
CLEANSTART-2026-DV49099
CLEANSTART-2026-GS57401
CLEANSTART-2026-NB51079
CLEANSTART-2026-OW14933
CLEANSTART-2026-SW34937
CLEANSTART-2026-TZ34913
CVE-2026-29786
GHSA-QFFP-2RHF-9H96

Affected Products

Confluence
Red Os
Node-Tar