Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

fstec логотип

BDU:2026-07231

Опубликовано: 20 фев. 2026
Источник: fstec
CVSS3: 7.1
CVSS2: 6.6
EPSS Низкий

Описание

Уязвимость библиотеки node-tar программной платформы Node.js связана с неверным ограничением имени пути к каталогу с ограниченным доступом. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, получить несанкционированный доступ к защищаемой информации

Вендор

Сообщество свободного программного обеспечения
Red Hat Inc.
ООО «Ред Софт»
Node.js Foundation

Наименование ПО

Debian GNU/Linux
Red Hat Openshift Data Foundation
Red Hat Developer Hub
РЕД ОС
Red Hat Trusted Artifact Signer
node-tar
Red Hat OpenShift Dev Spaces
Network Observability

Версия ПО

11 (Debian GNU/Linux)
4 (Red Hat Openshift Data Foundation)
- (Red Hat Developer Hub)
13 (Debian GNU/Linux)
8.0 (РЕД ОС)
1.3 (Red Hat Trusted Artifact Signer)
до 7.5.13 (node-tar)
3.27 (Red Hat OpenShift Dev Spaces)
1.11.2 (Network Observability)

Тип ПО

Операционная система
Прикладное ПО информационных систем
ПО программно-аппаратного средства

Операционные системы и аппаратные платформы

ООО «Ред Софт» РЕД ОС 8.0

Уровень опасности уязвимости

Средний уровень опасности (базовая оценка CVSS 2.0 составляет 6,6)
Высокий уровень опасности (базовая оценка CVSS 3.1 составляет 7,1)

Возможные меры по устранению уязвимости

Использование рекомендаций:
https://github.com/isaacs/node-tar
https://github.com/isaacs/node-tar/commit/2cb1120bcefe28d7ecc719b41441ade59c52e384
https://github.com/isaacs/node-tar/commit/d18e4e1f846f4ddddc153b0f536a19c050e7499f
https://github.com/isaacs/node-tar/security/advisories/GHSA-83g3-92jg-28cx
Для Ред ОС:
https://redos.red-soft.ru/search/?iblock_id=24&q=CVE-2026-26960
Для программных продуктов Red Hat Inc.:
https://access.redhat.com/security/cve/cve-2026-26960
Для Debian GNU/Linux:
https://security-tracker.debian.org/tracker/CVE-2026-26960

Статус уязвимости

Подтверждена производителем

Наличие эксплойта

Данные уточняются

Информация об устранении

Уязвимость устранена

Идентификаторы других систем описаний уязвимостей

EPSS

Процентиль: 21%
0.00288
Низкий

7.1 High

CVSS3

6.6 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

CVSS3: 7.1
redhat
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

CVSS3: 7.1
nvd
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

msrc
6 месяцев назад

node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction

CVSS3: 7.1
debian
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default option ...

EPSS

Процентиль: 21%
0.00288
Низкий

7.1 High

CVSS3

6.6 Medium

CVSS2