Security Advisory

CVE-2026-24842

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2026-01-28 00:20:13
Last updated 2026-01-28 14:56:10
Assigner GitHub_M
State PUBLISHED

Description

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.