CVE-2026-24842
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.
- Published Jan 28, 2026
- CVSS 8.2 high
- 0.6% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available
Affected software
- Red Hat 3scale API Management Platform
- Red Hat Advanced Cluster Management for Kubernetes
- Red Hat Cryostat
- Red Hat Enterprise Linux
- Red Hat JBoss Enterprise Application Platform
- Red Hat Logging Subsystem for Red Hat OpenShift
- Red Hat Multicluster Engine for Kubernetes
- Red Hat Network Observability
- Red Hat OpenShift Dev Spaces
- Red Hat Trusted Artifact Signer
- isaacs node-tar
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·