TopVuln

High-risk vulnerability digests

CVE-2026-29786

  • HIGH

MINI-79CC-CWG4-33HF

Details

CVSS v3
6.3
CVSS v4
8.2
NVD published
2026-03-07 16:15:55
EPSS
<0.1% probability · 0.7th percentile — 2026-05-01
Affected versions
cpe:2.3:a:isaacs:tar:*:*:*:*:*:node.js:*:*
Summary
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.
Remediation
Not available in our cache.
Exploit info
https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.