PT-2026-24117 · Node-Tar+2 · Node-Tar+2

Jvr2022

·

Published

2026-01-01

·

Updated

2026-05-18

·

CVE-2026-31802

CVSS v4.0

8.2

High

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions node-tar versions prior to 7.5.11
Description The node-tar software contains a flaw where it can be manipulated into creating a symbolic link that points outside the intended extraction directory. This is achieved by utilizing a drive-relative symlink target, such as C:../../../target.txt, during the tar extraction process using the tar.x() function. Successful exploitation allows for file overwrites outside of the current working directory.
Recommendations Update to node-tar version 7.5.11 or later.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-07258
CLEANSTART-2026-AD27625
CLEANSTART-2026-CB77162
CLEANSTART-2026-CE10526
CLEANSTART-2026-DU32240
CLEANSTART-2026-DV49099
CLEANSTART-2026-GS57401
CLEANSTART-2026-NB51079
CLEANSTART-2026-OW14933
CLEANSTART-2026-SW34937
CLEANSTART-2026-TZ34913
CVE-2026-31802
GHSA-9PPJ-QMQM-Q256

Affected Products

Confluence
Red Os
Node-Tar