6.1mediumMedium
CVE-2026-23745
Isaacs Tar
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.
Exploitation status
- Published references include exploit or proof-of-concept material. There is no confirmation it is being used in real attacks.
- A vendor advisory or patch reference has been published.
What the metrics mean
- It is requires local access to the machine.
- For an attacker who can reach it, no special conditions are needed to exploit it.
- To exploit it, no account is needed.
- Beyond that, someone has to be persuaded to take an action first.
Scoring
- CVSS
- 6.1 (v3.1)
- Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N- CVSS v4
- 8.2
- Weakness
- CWE-22
- Assigned by
- security-advisories@github.com
Dates
- Published
- 2026-01-16
- Last modified
- 2026-08-24
- Sources
- NVD
Affected products
- Isaacs Tar- 7.5.3
As listed in the NVD configuration data. Not a statement about your estate.
References
- https://github.com/isaacs/node-tar/commit/340eb285b6d986e91969a1170d7fe9b0face405e
- https://github.com/isaacs/node-tar/security/advisories/GHSA-8qq5-rm4j-mr97
- https://access.redhat.com/errata/RHSA-2026:18480
- https://access.redhat.com/errata/RHSA-2026:18868
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:2144
- https://access.redhat.com/errata/RHSA-2026:2900
- https://access.redhat.com/errata/RHSA-2026:2926
- https://access.redhat.com/errata/RHSA-2026:3782
- https://access.redhat.com/errata/RHSA-2026:41928
- https://access.redhat.com/errata/RHSA-2026:6192
- https://access.redhat.com/security/cve/CVE-2026-23745
- https://bugzilla.redhat.com/show_bug.cgi?id=2430538
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-23745.json