CVE-2026-26960Disclosure(isaacs / tar)

LOWCVSS 7.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tar

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-02-20); latest day: 2
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
tar

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-02-20: 4Mentions · 2026-02-25: 2Technical Details · 2026-02-20: 2Technical Details · 2026-02-25: 102-2002-25
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-204
Disclosure3General1
2026-02-252
Disclosure2
Full discourse6 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    Critical Vulnerabilities in Node-Tar and GnuPG Published https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26960

    Post summary

    Microsoft announced critical vulnerabilities in Node-Tar and GnuPG, referencing CVE-2026-26960.

    000421.1K
    151.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26960 Arbitrary File Read/Write Vulnerability in node-tar Tar Library Versions 7.5.7 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26960

    Post summary

    The entry announces an arbitrary file read/write vulnerability in node‑tar versions 7.5.7 and earlier, but provides no PoC, exploit code, or active exploitation evidence, nor does it mention any patch or workaround.

    0001047
    4.0K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-26960 (CVSS:7.1, HIGH) is Analyzed. node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-control..https://nvd.nist.gov/vuln/detail/CVE-2026-26960 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE‑2026‑26960, noting its CVSS score and affected node‑tar versions, but provides no PoC, exploit, or patch details.

    0000030
    172 followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-26960 impacts tar in 8 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/428 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A new high‑severity CVE‑2026-26960 affecting tar in AWS Lambda base images has been reported, with issue links for further details.

    0000030
    30 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26960 node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the e… https://www.cve.org/CVERecord?id=CVE-2026-26960

    Post summary

    The snippet describes CVE‑2026‑26960, noting that default options in node-tar v7.5.7 and below allow hardlink creation via an attacker‑controlled archive, but it offers no PoC, exploit code, or patch details.

    0000081
    56.4K followersView on X
  • Dylan Stone 🍋@NichNochma2
    General

    CVE-2026-26960

    Post summary

    The text only lists CVE-2026-26960 without any additional context or details.

    0000022
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appisaacstar-node.js-

Explore more