CVE-2026-29786

Description

node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.

Risk Information

Base Score
6.3
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.005

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 13.0.6.2Windows
Multiple Vulnerabilities are affected in IBM App Connect Enterprise 12.0.12.24Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234