CVE-2026-31802

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This vulnerability is fixed in 7.5.11.
Configurations

Configuration 1 (hide)

cpe:2.3:a:isaacs:tar:*:*:*:*:*:node.js:*:*

History

18 Mar 2026, 18:13

Type Values Removed Values Added
First Time Isaacs tar
Isaacs
References () https://github.com/isaacs/node-tar/commit/f48b5fa3b7985ddab96dc0f2125a4ffc9911b6ad - () https://github.com/isaacs/node-tar/commit/f48b5fa3b7985ddab96dc0f2125a4ffc9911b6ad - Vendor Advisory
References () https://github.com/isaacs/node-tar/security/advisories/GHSA-9ppj-qmqm-q256 - () https://github.com/isaacs/node-tar/security/advisories/GHSA-9ppj-qmqm-q256 - Exploit, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.5
CPE cpe:2.3:a:isaacs:tar:*:*:*:*:*:node.js:*:*

11 Mar 2026, 13:53

Type Values Removed Values Added
Summary
  • (es) node-tar es una implementación completa de Tar para Node.js. Antes de la versión 7.5.11, tar (npm) puede ser engañado para crear un enlace simbólico que apunta fuera del directorio de extracción utilizando un destino de enlace simbólico relativo a la unidad, como C:../../../target.txt, lo que permite la sobrescritura de archivos fuera del directorio de trabajo actual (cwd) durante la extracción normal de tar.x(). Esta vulnerabilidad está corregida en la versión 7.5.11.

10 Mar 2026, 18:19

Type Values Removed Values Added
References () https://github.com/isaacs/node-tar/security/advisories/GHSA-9ppj-qmqm-q256 - () https://github.com/isaacs/node-tar/security/advisories/GHSA-9ppj-qmqm-q256 -

10 Mar 2026, 07:44

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-10 07:44

Updated : 2026-03-18 18:13


NVD link : CVE-2026-31802

Mitre link : CVE-2026-31802

CVE.ORG link : CVE-2026-31802


JSON object : View

Products Affected

isaacs

  • tar
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')