Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-29786

27
FAUCET Score

CVE-2026-29786 describes a path traversal vulnerability in node-tar versions prior to 7.5.10, allowing an attacker to create hardlinks outside the intended extraction directory during tar.x() operations. This can lead to arbitrary file overwrites on the system. The vulnerability carries a high CVSS score of 8.2, indicating a significant impact on integrity and availability, with a low attack complexity requiring user interaction. Currently, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.5.10CPE matchmatch criteria
cpe:2.3:a:isaacs:tar:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 4.0

8.2HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
HIGH
SS Availability
LOW
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.41%
Probability of exploitation in next 30 days
EPSS Percentile
33.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0041 is in the 40th percentile among its peer group of 5,758 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

npmpatch availablevia ghsa
Product: tarFixed in: 7.5.10

Vendor Advisories (2)

microsoft2026-Mar/CVE-2026-29786Important

node-tar: Hardlink Path Traversal via Drive-Relative Linkpath

Mar 10, 2026
npmGHSA-qffp-2rhf-9h96high

tar has Hardlink Path Traversal via Drive-Relative Linkpath

Mar 5, 2026

References

access.redhat.com / security/cve/CVE-2026-29786
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-29786.json
github.com / isaacs/node-tar/commit/7bc755dd85e623c0279e08eb3784909e6d7e4b9f
Patch
github.com / isaacs/node-tar/security/advisories/GHSA-qffp-2rhf-9h96
ExploitVendor Advisory