| Package | node-tar |
|---|---|
| Version | 4.4.6+ds1-3+deb10u3 (buster) |
| Related CVEs | CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786 |
Multiple vulnerabilities have been discovered in node-tar, a Node.js module to read and write portable tar archives.
- CVE-2024-28863
-
Generating a large number of sub-folders can consume memory on the system and even crash the Node.js client within a few seconds using a path with too many sub-folders inside.
- CVE-2026-23745
-
When preservePaths is false, the linkpath of Link (hardlink) and SymbolicLink entries fail to be sanitized, allowing malicious archives to bypass the extraction root restriction, leading to arbitrary file overwrites via hardlinks and symlink poisoning via absolute symlink targets.
The fix for this issue introduces CVE-2026-24842 and CVE-2026-31802. Both have been fixed subsequently.
- CVE-2026-26960
-
An attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, enabling arbitrary file read and write as the extracting user.
- CVE-2026-29786
-
An attacker-controlled archive can create a hardlink that points outside the extraction directory by using a drive-relative link target.
For Debian 10 buster, these problems have been fixed in version 4.4.6+ds1-3+deb10u3.
We recommend that you upgrade your node-tar packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.