PatchSiren cyber security CVE debrief
CVE-2026-29786 isaacs CVE debrief
CVE-2026-29786 is a high-severity vulnerability in node-tar, a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. The CVE was published on March 7, 2026, and modified on June 30, 2026.
- Vendor
- isaacs
- Product
- node-tar
- CVSS
- HIGH 8.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-03-07
- Original CVE updated
- 2026-09-01
- Advisory published
- 2026-03-07
- Advisory updated
- 2026-09-01
Who should care
Developers and administrators using node-tar in their applications should be aware of this vulnerability and take immediate action to patch. The vulnerability allows for file overwrite outside the current working directory, which can lead to security breaches. Node-tar users should prioritize patching to prevent potential attacks.
Technical summary
The vulnerability in node-tar allows an attacker to create a hardlink that points outside the extraction directory using a drive-relative link target. This enables file overwrite outside the current working directory during normal tar.x() extraction. The issue has been patched in version 7.5.10. The CVSS vector for this vulnerability is CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X.
Defensive priority
High priority should be given to patching node-tar to version 7.5.10 or later. Additionally, defenders should monitor for potential attacks and implement compensating controls to prevent file overwrites.
Recommended defensive actions
- Patch node-tar to version 7.5.10 or later
- Monitor for potential attacks
- Implement compensating controls to prevent file overwrites
- Review and update security configurations
- Perform vulnerability scanning and inventory checks
Evidence notes
The CVE-2026-29786 vulnerability was published on March 7, 2026, and modified on June 30, 2026. The vulnerability has a CVSS score of 8.2 and is classified as HIGH. The issue has been patched in version 7.5.10 of node-tar.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-29786 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-29786
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-29786 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-29786
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f
[email protected] - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/security/cve/CVE-2026-29786
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29786.json
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.