Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-24842

30
FAUCET Score

CVE-2026-24842 is a path traversal vulnerability affecting node-tar versions prior to 7.5.7, allowing an attacker to create hardlinks to arbitrary files outside the intended extraction directory. This high-severity vulnerability (CVSS 8.2) can be exploited remotely with low complexity, requiring user interaction, potentially leading to high confidentiality impact. While there is no known active exploitation or public exploit code, the vulnerability has received some community attention, with a fix available in version 7.5.7.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.5.7CPE matchmatch criteria
cpe:2.3:a:isaacs:tar:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.54%
Probability of exploitation in next 30 days
EPSS Percentile
42.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0054 is in the 44th percentile among its peer group of 14,875 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: tarFixed in: 7.5.7
redhatpatch availablevia redhat_api
Product: Network Observability (NETOBSERV) 1.11.0Fixed in: network-observability/network-observability-console-plugin-rhel9:sha256:bb0f0e05c7bb037cd07c260a8fcea50fb62cc433d8cd504c4bb065f994c359c6
View patch
redhatpatch availablevia redhat_api
Product: Network Observability (NETOBSERV) 1.11.0Fixed in: network-observability/network-observability-console-plugin-compat-rhel9:sha256:17be6b67f5ed6757b65df0d59dc5d59130ee2e3510c60453de77fadfd7ca3c16
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: linux-sgx
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/mcg-core-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/ocs-client-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat Openshift Data Foundation 4Fixed in: odf4/odf-multicluster-console-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/code-rhel9
redhatno patchvia redhat_api
Product: Red Hat OpenShift Dev SpacesFixed in: devspaces/dashboard-rhel9
redhatno patchvia redhat_api
Product: Red Hat Trusted Artifact SignerFixed in: rhtas/rekor-search-ui-rhel9
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: linux-sgx
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp26/system
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel7
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel8
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp2/system-rhel9
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.apicurio-apicurito
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-hawtio-online
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.hawt-project
redhatend of lifevia redhat_api
Product: Red Hat Fuse 7Fixed in: io.syndesis-syndesis-parent
redhatend of lifevia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-operator-bundle
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch6-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-proxy-rhel9
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/elasticsearch-rhel9-operator
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/kibana6-rhel8
redhatend of lifevia redhat_api
Product: Logging Subsystem for Red Hat OpenShiftFixed in: openshift-logging/logging-curator5-rhel9
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp20/system
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp21/system
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp22/system
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp24/system
redhatend of lifevia redhat_api
Product: Red Hat 3scale API Management Platform 2Fixed in: 3scale-amp25/system

Vendor Advisories (2)

npmGHSA-34x7-hfp2-rc4vhigh

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Jan 28, 2026
redhatCVE-2026-24842Important

node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check

Jan 28, 2026

References

access.redhat.com / errata/RHSA-2026:18480
access.redhat.com / errata/RHSA-2026:18868
access.redhat.com / errata/RHSA-2026:2900
access.redhat.com / errata/RHSA-2026:33371
access.redhat.com / errata/RHSA-2026:5447
access.redhat.com / errata/RHSA-2026:6192
access.redhat.com / security/cve/CVE-2026-24842
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-24842.json
github.com / isaacs/node-tar/commit/f4a7aa9bc3d717c987fdf1480ff7a64e87ffdb46
Patch
github.com / isaacs/node-tar/security/advisories/GHSA-34x7-hfp2-rc4v
ExploitVendor Advisory