PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-29786 isaacs CVE debrief

CVE-2026-29786 is a high-severity vulnerability in node-tar, a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. The CVE was published on March 7, 2026, and modified on June 30, 2026.

Vendor
isaacs
Product
node-tar
CVSS
HIGH 8.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-03-07
Original CVE updated
2026-09-01
Advisory published
2026-03-07
Advisory updated
2026-09-01

Who should care

Developers and administrators using node-tar in their applications should be aware of this vulnerability and take immediate action to patch. The vulnerability allows for file overwrite outside the current working directory, which can lead to security breaches. Node-tar users should prioritize patching to prevent potential attacks.

Technical summary

The vulnerability in node-tar allows an attacker to create a hardlink that points outside the extraction directory using a drive-relative link target. This enables file overwrite outside the current working directory during normal tar.x() extraction. The issue has been patched in version 7.5.10. The CVSS vector for this vulnerability is CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.

Defensive priority

High priority should be given to patching node-tar to version 7.5.10 or later. Additionally, defenders should monitor for potential attacks and implement compensating controls to prevent file overwrites.

Recommended defensive actions

  • Patch node-tar to version 7.5.10 or later
  • Monitor for potential attacks
  • Implement compensating controls to prevent file overwrites
  • Review and update security configurations
  • Perform vulnerability scanning and inventory checks

Evidence notes

The CVE-2026-29786 vulnerability was published on March 7, 2026, and modified on June 30, 2026. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. The issue has been patched in version 7.5.10 of node-tar.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-29786 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-29786

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-29786 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-29786

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f

    [email protected] - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-29786

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29786.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.