Executive brief
node-tar is a Node.js library used to extract and create tar archives, commonly used in build systems and package management. A flaw in symlink handling allows an attacker to craft a malicious tar file that creates symlinks pointing outside the intended extraction directory, enabling arbitrary file overwrite with the permissions of the extracting process. This could compromise build pipelines, services processing user-supplied archives, or CLI tools.
Technical details
This is a symlink path traversal vulnerability in the tar extraction logic. The vulnerable code in Unpack[STRIPABSOLUTEPATH] validates path traversal attempts (..) against a resolved path that still contains the original drive-relative value (e.g., "C:../../../target.txt"), but after validation rewrites the path to the stripped form ("../../../target.txt"). When the symlink is created, it uses the rewritten relative path, which when evaluated from within a nested directory structure (e.g., "a/b/l"), successfully escapes the extraction root. The attack is reachable during normal tar.x({ cwd, file }) extraction of attacker-controlled archives and requires no authentication or special privileges. Patch version 7.5.11 addresses the issue.
Affected products
- npm tar <= 7.5.10
Timeline
- 2026-03-09: disclosed
- 2026-03-09: patched: Version 7.5.11 released