CVE-2026-26960 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside…
High CVSS: 7.1

CVE-2026-26960

node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user. Severity is high because the primitive bypasses path protections and turns archive extraction into a direct filesystem access primitive. This issue has been fixed in version 7.5.8.
Vendor
Isaacs
Product
Tar
CWE
CWE-22
Yayın Tarihi
2026-02-20 02:16:53
Güncelleme
2026-02-20 19:24:16
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar