CVE-2026-31802
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.
- Affected products
- Confluence, Red Os, Node-Tar
- Isaacs Tar
- < 7.5.11
- Fix
- Available
- CVSS 4.0
- 8.2 HIGH
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.3% (17th percentile)
- Weakness
- CWE-22
- NVD status
- Analyzed
- Published
- 2026-03-09
CVE-2026-31802 at NVD
5 known exploits for CVE-2026-31802
Proof-of-concept code and exploit modules indexed by Sploitus