Sploitus

CVE-2026-31802

5 known exploits for CVE-2026-31802

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.

Affected products
Confluence, Red Os, Node-Tar
Isaacs Tar
< 7.5.11
Fix
Available
CVSS 4.0
8.2 HIGH
CVSS 3.1
5.5 MEDIUM
EPSS
0.3% (17th percentile)
Weakness
CWE-22
NVD status
Analyzed
Published
2026-03-09
CVE-2026-31802 at NVD
Authoritative description, scoring and affected products

5 known exploits for CVE-2026-31802

Proof-of-concept code and exploit modules indexed by Sploitus