
Critical Vulnerabilities in Node-Tar and GnuPG Published https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26960
Post summary
Microsoft announced critical vulnerabilities in Node-Tar and GnuPG, referencing CVE-2026-26960.
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.
Priority
LOW
Exploitation
NONE
PoC
YES
Patch
AVAILABLE
Momentum
STABLE
If you run products in this scope, you should treat this CVE as relevant to your environment.
| Date | Total | Labels |
|---|
| 2026-02-20 | 4 | Disclosure3General1 |
| 2026-02-25 | 2 | Disclosure2 |

Critical Vulnerabilities in Node-Tar and GnuPG Published https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-26960
Post summary
Microsoft announced critical vulnerabilities in Node-Tar and GnuPG, referencing CVE-2026-26960.

CVE-2026-26960 Arbitrary File Read/Write Vulnerability in node-tar Tar Library Versions 7.5.7 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26960
Post summary
The entry announces an arbitrary file read/write vulnerability in node‑tar versions 7.5.7 and earlier, but provides no PoC, exploit code, or active exploitation evidence, nor does it mention any patch or workaround.

CVE-2026-26960 (CVSS:7.1, HIGH) is Analyzed. node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-control..https://nvd.nist.gov/vuln/detail/CVE-2026-26960 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
Post summary
The post references CVE‑2026‑26960, noting its CVSS score and affected node‑tar versions, but provides no PoC, exploit, or patch details.

🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-26960 impacts tar in 8 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/428 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
Post summary
A new high‑severity CVE‑2026-26960 affecting tar in AWS Lambda base images has been reported, with issue links for further details.

CVE-2026-26960 node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the e… https://www.cve.org/CVERecord?id=CVE-2026-26960
Post summary
The snippet describes CVE‑2026‑26960, noting that default options in node-tar v7.5.7 and below allow hardlink creation via an attacker‑controlled archive, but it offers no PoC, exploit code, or patch details.

CVE-2026-26960
Post summary
The text only lists CVE-2026-26960 without any additional context or details.
1 of 1 entries
| Part | Vendor | Product | Version | Target SW | Target HW |
|---|---|---|---|---|---|
| App | isaacs | tar | - | node.js | - |