CVE detail
CVE-2026-24842
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.9 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
11 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24842.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJan 28, 2026, 1:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2433645bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/security/cve/CVE-2026-24842access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:6192access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:5447access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:33371access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:2900access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:18868access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM - https://access.redhat.com/errata/RHSA-2026:18480access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJan 28, 2026, 1:16 AM No excerpt available.
Exploitgithub.comJan 28, 2026, 1:16 AMNo excerpt available.
Exploitgithub.comJan 28, 2026, 1:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-29786CVSS 8.2 · High
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-rel…
- CVE-2026-47121CVSS 6.1 · Medium
Sparkle is a software update framework for macOS. Prior to version 2.9.2, `Autoupdate/SUBinaryDeltaApply.m` enforces `relativePath.pathComponents containsObject:@".."` and rejects…
- CVE-2026-58414CVSS 5.5 · Medium
Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.12.2, `EnvironmentManager.backup()` recursively collects files using `_collectBackupFiles()`. `_col…
- CVE-2026-50163CVSS 7.1 · High
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but re…
- CVE-2026-53535CVSS 5.9 · Medium
Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the git-sync feature clones a user-configured Git repository into a temporary directory on the ser…
- CVE-2026-53486CVSS 9.1 · Critical
The decompress package for Node.js extracts archives. Prior to 10.2.1 and 11.1.3, archive extraction can create files and links outside the target directory. When extracting an ar…