Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-29786

Опубликовано: 07 мар. 2026
Источник: redhat
CVSS3: 8.6

Описание

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

A flaw was found in node-tar. A hardlink that points outside the extraction directory can be created by using a drive-relative link target such as C:../target.txt, allowing a file overwrite outside the current working directory during normal tar.x() extraction.

Отчет

To exploit this flaw, an attacker must be able to supply a specially crafted archive to be processed by an application using node-tar. Additionally, this vulnerability allows files to be extracted outside the intended directory but it is still limited to the permissions of the node-tar application processing the archive. Due to this reason, this flaw has been rated with an important severity. This vulnerability does not affect node-tar running on Unix-like systems as it relies on a drive-relative link target to be exploited.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-compat-rhel9Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp20/systemNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2445476node-tar: hardlink path traversal via drive-relative linkpath

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
19 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

CVSS3: 6.3
nvd
19 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

msrc
16 дней назад

node-tar: Hardlink Path Traversal via Drive-Relative Linkpath

CVSS3: 6.3
debian
19 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, ...

github
22 дня назад

tar has Hardlink Path Traversal via Drive-Relative Linkpath

8.6 High

CVSS3