node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.
CVSS Details
- CVSS 4.0 Base Score: 8.2 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade sgx-pccs-adminUpgrade sgx-pckid-toolUpgrade tdx-qgsUpgrade sgx-libsUpgrade sgx-commonUpgrade sgx-mpaUpgrade sgx-pccs | May 27, 2026 | May 19, 2026 |
| Amazon_linux_2023 | — | Upgrade nodejs22-libs-debuginfoUpgrade nodejs24-debugsourceUpgrade nodejs22-debuginfoUpgrade v8-13.6-develUpgrade nodejs20-develUpgrade v8-11.3-develUpgrade nodejs24-libs-debuginfoUpgrade nodejs22-full-i18nUpgrade nodejs24-docsUpgrade nodejs20-npmUpgrade nodejs24-full-i18nUpgrade v8-12.4-develUpgrade nodejs20Upgrade nodejs24-debuginfoUpgrade nodejs20-debuginfoUpgrade nodejs20-libs-debuginfoUpgrade nodejs22-debugsourceUpgrade nodejs20-libsUpgrade nodejs22-npmUpgrade nodejs22Upgrade nodejs24-libsUpgrade nodejs22-libsUpgrade nodejs20-docsUpgrade nodejs22-develUpgrade nodejs22-docsUpgrade nodejs24-develUpgrade nodejs24Upgrade nodejs20-full-i18nUpgrade nodejs24-npmUpgrade nodejs20-debugsource | Mar 9, 2026 | Jan 16, 2026 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Mar 18, 2026 | Mar 17, 2026 |
| Debian | — | Upgrade node-tar | Apr 29, 2026 | Apr 29, 2026 |
| Red Hat Jboss Eap | — | — | Jan 21, 2026 | Jan 16, 2026 |
| Redhat_linux | — | No solution existsUpgrade sgx-libs-debuginfoUpgrade sgx-commonUpgrade sgx-mpaUpgrade linux-sgx-debuginfoUpgrade sgx-pccs-adminUpgrade sgx-pccsUpgrade sgx-mpa-debuginfoUpgrade sgx-libsUpgrade linux-sgx-debugsourceUpgrade tdx-attest-libs-debuginfoUpgrade tdx-qgs-debuginfoUpgrade tdx-qgsUpgrade sgx-pckid-toolUpgrade sgx-pccs-debuginfoUpgrade sgx-pckid-tool-debuginfoUpgrade sgx-enclave-devel-debuginfo | May 20, 2026 | Jan 16, 2026 |
| Rocky_linux | — | Upgrade sgx-libsUpgrade sgx-pccs-adminUpgrade tdx-qgs-debuginfoUpgrade sgx-libs-debuginfoUpgrade sgx-pccsUpgrade sgx-pccs-debuginfoUpgrade sgx-pckid-toolUpgrade sgx-mpa-debuginfoUpgrade linux-sgx-debugsourceUpgrade sgx-commonUpgrade sgx-pckid-tool-debuginfoUpgrade tdx-qgsUpgrade linux-sgx-debuginfoUpgrade sgx-mpa | Jun 1, 2026 | May 28, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub