Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26960

Опубликовано: 20 фев. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

A flaw was found in node-tar. An attacker can craft a malicious archive that, when extracted with default options, creates a hardlink outside the intended extraction directory. This vulnerability allows the attacker to perform arbitrary file read and write operations as the user extracting the archive, bypassing existing path protections. This can lead to unauthorized access and modification of sensitive system files.

Отчет

In Red Hat environments, this condition introduces a significant constraint, as exploitation requires user interaction and reliance on unsafe handling of externally supplied archives. The attack is not remotely exploitable in isolation and depends on a user or service processing attacker-controlled input. Furthermore, the impact of the vulnerability is limited to the privileges of the extracting process. In typical Red Hat deployments, archive extraction is performed by non-privileged users or within confined environments such as containers or restricted service contexts, which limits the scope of potential damage. Red Hat analysis also notes that this issue does not provide a direct mechanism for code execution or privilege escalation, but rather enables file system manipulation within the boundaries of the executing user’s permissions. Given the requirement for user-assisted exploitation, the absence of a direct remote attack vector, and the confinement of impact to the privileges of the extracting process, Red Hat considers the practical risk to be lower than the generalized NVD assessment. As a result, this vulnerability is classified as Moderate severity.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Will not fix
Red Hat 3scale API Management Platform 23scale-amp20/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp21/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp22/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp24/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp25/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp26/systemWill not fix
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Will not fix
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Will not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2441253node-tar: node-tar: Arbitrary file read/write via malicious archive hardlink creation

EPSS

Процентиль: 21%
0.00288
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
ubuntu
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

CVSS3: 7.1
nvd
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

msrc
6 месяцев назад

node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction

CVSS3: 7.1
debian
6 месяцев назад

node-tar is a full-featured Tar for Node.js. When using default option ...

CVSS3: 7.1
github
6 месяцев назад

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

EPSS

Процентиль: 21%
0.00288
Низкий

7.1 High

CVSS3