CVE-2026-23745Path Traversal in Node-tar

CWE-22Path Traversal9 documents8 sources
Severity
8.2HIGHNVD
EPSS
0.0%
top 99.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 16

Description

node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets. This vulnerability is fixed in 7.5.3.

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N

Affected Packages4 packages

CVEListV5isaacs/node-tar< 7.5.3
Debianisaacs/node-tar< 6.2.1+ds1+~cs6.1.13-6
npmgnu/tar< 7.5.3
NVDisaacs/tar< 7.5.3

Patches

🔴Vulnerability Details

4
OSV
CVE-2026-23745: node-tar is a Tar for Node2026-01-16
GHSA
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization2026-01-16
OSV
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization2026-01-16
CVEList
node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization2026-01-16

📋Vendor Advisories

2
Red Hat
node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives2026-01-16
Debian
CVE-2026-23745: node-tar - node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-23745 Impact, Exploitability, and Mitigation Steps | Wiz

💬Community

1
Bugzilla
CVE-2026-23745 node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives2026-01-16
CVE-2026-23745 — Path Traversal in Isaacs Node-tar | cvebase