Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-31802

Опубликовано: 09 мар. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.

A flaw was found in tar. An attacker can exploit this vulnerability by crafting a malicious tar archive containing a drive-relative symlink. This symlink, such as C:../../../target.txt, can trick the tar utility into writing files outside the intended extraction directory during normal archive extraction, leading to unauthorized file overwrite.

Отчет

This is a MODERATE impact vulnerability. The tar utility is susceptible to unauthorized file overwrites when processing specially crafted archives containing drive-relative symlinks. As such, it primarily affects integrity (since it can overwrite files and file contents), with no clear indication that availability or confidentiality may be affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4io.cryostat-cryostatAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch6-rhel9Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-operator-bundleOut of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-proxy-rhel9Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/elasticsearch-rhel9-operatorOut of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Out of support scope
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-curator5-rhel9Out of support scope
Network Observability Operatornetwork-observability/network-observability-console-plugin-compat-rhel9Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Not affected
Red Hat 3scale API Management Platform 23scale-amp20/systemOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2445881tar: tar: File overwrite via drive-relative symlink traversal

EPSS

Процентиль: 0%
0.00007
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
17 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.

CVSS3: 5.5
nvd
17 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.

msrc
13 дней назад

node-tar Symlink Path Traversal via Drive-Relative Linkpath

CVSS3: 5.5
debian
17 дней назад

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, ...

github
16 дней назад

node-tar Symlink Path Traversal via Drive-Relative Linkpath

EPSS

Процентиль: 0%
0.00007
Низкий

6.2 Medium

CVSS3