THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-24842 (HIGH 8.2) — node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that b

[NVD] CVE-2026-24842 (HIGH 8.2) — node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that b

lownvdPublished 2026-01-28

CVE-2026-24842 CVSS: 8.2 HIGH Published: 2026-01-28T01:16:14.947

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlin

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-24842