CVE-2026-29786Disclosure(isaacs / tar)

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch isaacs tar systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-59

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tar

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-07); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
tar

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-07: 2Mentions · 2026-03-08: 1Mentions · 2026-03-09: 1Mentions · 2026-03-12: 1Patch / Workaround · 2026-03-07: 1Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-12: 103-0703-0803-0903-12
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-072
Disclosure2
2026-03-081
Disclosure1
2026-03-091
General1
2026-03-121
Disclosure1
Full discourse5 posts
  • Cyber Threat Observatory | Alan Turing Institute@TuringCyberObs
    General

    New analysis: CVE-2026-29786 enables hardlink path traversal allowing file overwrite outside the extraction directory. High impact where services extract attacker-supplied archives. Full Analysis: https://lnkd.in/ejx7jZJt #ThreatIntelligence #SupplyChainSecurity #CyberSecurity

    Post summary

    The tweet announces a new analysis of CVE‑2026‑29786, highlighting its hardlink path‑traversal flaw that permits file overwrite outside the extraction directory, with no mention of exploits, patches, or active attacks.

    0001255
    44 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29786 Arbitrary File Overwrite Vulnerability in node-tar Before 7.5.10 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29786

    Post summary

    The post announces an arbitrary file overwrite vulnerability affecting node-tar versions prior to 7.5.10 and points to a vulnerability details page.

    0001141
    4.0K followersView on X
  • Lambda Watchdog@LambdaWatchdog
    Disclosure

    🚨 New HIGH CVE detected in AWS Lambda 🚨 CVE-2026-29786 impacts tar in 4 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/446 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless

    Post summary

    A newly announced high‑severity CVE (CVE‑2026‑29786) affecting tar in AWS Lambda base images is disclosed, but the information provided lacks a PoC, exploit code, active exploitation evidence, or remediation guidance.

    0001048
    31 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29786 node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by usin… https://www.cve.org/CVERecord?id=CVE-2026-29786

    Post summary

    Node‑tar before 7.5.10 allows creation of hardlinks outside the extraction directory, a vulnerability mitigated in later releases.

    00010105
    56.6K followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 node-tar, Link Following, #CVE-2026-29786 (High) https://dailycve.com/node-tar-link-following-cve-2026-29786-high/

    Post summary

    The post announces a high‑severity CVE-2026-29786 affecting node‑tar’s link following behavior and provides a link to a DailyCVE article summarizing the issue.

    0000028
    167 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appisaacstar-node.js-

Explore more