Executive brief
node-tar is a popular software library used by Node.js applications to create and extract compressed archive files. A security flaw allows a specially crafted archive to create file links that point outside of the intended folder. If an application or user extracts such an archive, an attacker could overwrite sensitive files on the system, potentially leading to system instability or unauthorized configuration changes.
Technical details
A path traversal vulnerability exists in node-tar's hardlink extraction logic. The 'Unpack' component fails to properly sanitize drive-relative link targets (e.g., 'C:../target.txt') because it checks for directory traversal segments ('..') before stripping absolute drive roots. An attacker can provide a malicious tar archive that, when extracted via tar.x(), creates a hardlink pointing outside the current working directory. Subsequent writes to the extracted link will overwrite the target file with the permissions of the Node.js process. This issue is resolved in version 7.5.10 by ensuring absolute roots are stripped before path sanitization.
Affected products
- isaacs (npm) tar < 7.5.10
Timeline
- 2026-03-04: advisory: GitHub Security Advisory GHSA-qffp-2rhf-9h96 published
- 2026-03-04: patched: Fix committed to repository and released in version 7.5.10
- 2026-03-07: disclosed: CVE-2026-29786 published to NVD
References
- https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f
- https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96
- https://access.redhat.com/security/cve/CVE-2026-29786
- https://bugzilla.redhat.com/show_bug.cgi?id=2445476
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29786.json