CVE Database
/

CVE-2026-29786

Back to search

CVE-2026-29786

Published: Mar 7, 2026

Modified: Mar 9, 2026

PUBLISHED

Description

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

VendorProductVersions

isaacs

node-tar

affected
< 7.5.10

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now