CVE-2026-24842Disclosure(isaacs / tar)

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isaacs tar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tar

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-01-28); latest day: 1
  • 7 total mentions across 5 days

Affected systems

Vendors
Products
tar

Deep dive

Activity timeline7 mentions / 5d
01223Mentions · 2026-01-28: 3Mentions · 2026-01-29: 1Mentions · 2026-02-02: 1Mentions · 2026-02-11: 1Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-11: 1Technical Details · 2026-01-28: 3Technical Details · 2026-02-02: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-18: 101-2801-2902-0202-1102-18
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-01-283
Disclosure2General1
2026-01-291
General1
2026-02-021
Disclosure1
2026-02-111
Patch1
2026-02-181
Disclosure1
Full discourse7 posts
  • 리유@R_E_Y_O_U
    General

    에바 참친데 CVE-2026-24842 https://github.com/isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v

    Post summary

    The post merely references CVE-2026-24842 and links to its GitHub advisory, offering no further technical or exploit information.

    20020258
    758 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Node Tar, Path Traversal, #CVE-2026-24842 (High) https://dailycve.com/node-tar-path-traversal-cve-2026-24842-high/

    Post summary

    The tweet announces a high‑severity Path Traversal vulnerability in Node‑Tar (CVE‑2026‑24842) and links to a dailycve article, but it does not provide any PoC, exploit code, or mitigation information.

    0000036
    162 followersView on X
  • levi.notes@levi_notes
    Patch

    🚨 Node.js security alert (CVE-2026-24842) node-tar vulnerability allows malicious TAR files to access files outside extraction directories. 👉 Possible via npm install 👉 Risk of credential / SSH key leaks 👉 Upgrade to node-tar 7.5.7+ #Security #NodeJS #SupplyChainAttack

    Post summary

    Node-tar vulnerability (CVE-2026-24842) allows malicious TAR files to escape extraction directories and potentially leak credentials; users are advised to upgrade to version 7.5.7 or later.

    0000070
    4 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-24842 (CVSS:8.2, HIGH) is Undergoing Analysis. node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink en..https://nvd.nist.gov/vuln/detail/CVE-2026-24842 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces CVE-2026-24842, noting its high severity and affected node‑tar versions, but does not provide PoC, exploit, or patch information.

    0000049
    171 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24842: Escape Artist: Breaking node-tar with Hardlink Path Traversal A critical logic flaw in node-tar, the de facto standard archive utility for the Node.js ecosystem, allows attackers to bypass path traversal protections using hardlinks. By... https://cvereports.com/reports/CVE-2026-24842

    Post summary

    A critical logic flaw in node‑tar allows hardlinks to bypass path traversal protections, enabling potential arbitrary file extraction. The report highlights the vulnerability but does not provide a PoC, exploit, or mitigation.

    0000028
    29 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24842 Path Traversal Vulnerability in node-tar Allowing Hardlink Creation Outside Extraction Directory https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24842

    Post summary

    The post reports a path traversal flaw in node-tar (CVE‑2026‑24842) that permits creation of hardlinks beyond the intended extraction directory, potentially enabling unauthorized file access.

    0000074
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24842 node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics… https://www.cve.org/CVERecord?id=CVE-2026-24842

    Post summary

    The post announces CVE-2026-24842 affecting node-tar versions older than 7.5.7 due to a hardlink path resolution flaw, with no PoC, exploit, or patch details shared.

    00000221
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appisaacstar-node.js-

Explore more