CVE-2026-24842
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
- Affected products
- Confluence, Rocky Linux, Node-Tar
- Isaacs Tar
- < 7.5.7
- Fix
- Available
- CVSS 3.1
- 8.2 HIGH
- EPSS
- 0.5% (42th percentile)
- Weakness
- CWE-59, CWE-22
- NVD status
- Modified
- Published
- 2026-01-28
CVE-2026-24842 at NVD
No indexed exploits for CVE-2026-24842 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-24842 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.