node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.
CVSS Details
- CVSS 4.0 Base Score: 8.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade sgx-pccsUpgrade sgx-mpaUpgrade sgx-commonUpgrade sgx-pckid-toolUpgrade sgx-libsUpgrade tdx-qgsUpgrade sgx-pccs-admin | May 27, 2026 | May 19, 2026 |
| Amazon_linux_2023 | — | Upgrade v8-11.3-develUpgrade nodejs20-npmUpgrade nodejs24-full-i18nUpgrade v8-12.4-develUpgrade nodejs24-docsUpgrade nodejs20-develUpgrade nodejs20Upgrade nodejs24-libs-debuginfoUpgrade nodejs22-full-i18nUpgrade nodejs24-debuginfoUpgrade nodejs20-debuginfoUpgrade v8-13.6-develUpgrade nodejs22-libs-debuginfoUpgrade nodejs20-libs-debuginfoUpgrade nodejs22-debuginfoUpgrade nodejs24-debugsourceUpgrade nodejs20-libsUpgrade nodejs22-develUpgrade nodejs22-npmUpgrade nodejs24Upgrade nodejs22-debugsourceUpgrade nodejs24-develUpgrade nodejs20-docsUpgrade nodejs24-libsUpgrade nodejs20-full-i18nUpgrade nodejs20-debugsourceUpgrade nodejs22-docsUpgrade nodejs22Upgrade nodejs22-libsUpgrade nodejs24-npm | Mar 9, 2026 | Jan 16, 2026 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Mar 18, 2026 | Mar 17, 2026 |
| Debian | — | Upgrade node-tar | Apr 29, 2026 | Apr 29, 2026 |
| Red Hat Jboss Eap | — | — | Jan 21, 2026 | Jan 16, 2026 |
| Redhat_linux | — | Upgrade sgx-commonUpgrade sgx-libs-debuginfoUpgrade sgx-mpaNo solution existsUpgrade sgx-pckid-tool-debuginfoUpgrade linux-sgx-debuginfoUpgrade linux-sgx-debugsourceUpgrade sgx-pccs-adminUpgrade sgx-libsUpgrade tdx-qgs-debuginfoUpgrade sgx-pccsUpgrade sgx-pckid-toolUpgrade tdx-attest-libs-debuginfoUpgrade sgx-mpa-debuginfoUpgrade sgx-enclave-devel-debuginfoUpgrade sgx-pccs-debuginfoUpgrade tdx-qgs | May 20, 2026 | Jan 16, 2026 |
| Rocky_linux | — | Upgrade sgx-mpaUpgrade sgx-commonUpgrade tdx-qgsUpgrade linux-sgx-debuginfoUpgrade linux-sgx-debugsourceUpgrade sgx-pckid-tool-debuginfoUpgrade sgx-libsUpgrade sgx-mpa-debuginfoUpgrade sgx-pckid-toolUpgrade sgx-pccs-debuginfoUpgrade sgx-pccs-adminUpgrade tdx-qgs-debuginfoUpgrade sgx-pccsUpgrade sgx-libs-debuginfo | Jun 1, 2026 | May 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub