Listen to this Post
CVE-2026-31802 is a security flaw.
It affects node-tar in Node.js.
Versions prior to 7.5.11 are vulnerable.
The issue involves symlink path traversal.
It allows arbitrary file overwrite outside cwd.
During standard tar.x() archive extraction,
malicious archives can be crafted by attackers.
The core vulnerability arises from inconsistent handling.
Linkpath values are treated differently during checks.
Drive-relative paths such as C:../../../target.txt are used.
The sanitization logic strips the drive prefix.
This rewrites the path into ../../../target.txt format.
However, validation checks evaluate the original raw value.
Because of this mismatch, the malicious entry passes.
The archive extraction accepts the crafted link entry.
Once extracted, the symlink points outside the directory.
Subsequent write operations through this link succeed.
Data is written to files outside the extraction root.
This turns normal extraction into an overwrite primitive.
CLI tools and update pipelines are major targets.
Services consuming untrusted tar files face high risks.
Attackers can target system configuration or scripts.
Execution happens with user process permissions.
Fixing the issue requires proper path validation alignment.
Developers must ensure checked and written paths match.
The vulnerability received a medium severity score.
Aqua Security and NVD documented the technical metrics.
Security researchers published complete proof of concepts.
Upgrading dependencies resolves the directory traversal vector.
Immediate patching protects applications from external file corruption.
DailyCVE Form:
Platform: Node.js npm tar
Version: Before 7.5.11
Vulnerability: Path Traversal Symlink
Severity: Medium Risk
date: March 10 2026
Prediction: Patched in March
(end of form)
What Undercode Say:
npm install [email protected] node -e "const tar = require('tar'); tar.x({ file: 'malicious.tar' })"
const tar = require('tar');
tar.x({ file: 'exploit.tar', cwd: './extract' });
Exploit: (Educational Purposes!)
python3 -c "
import tarfile
with tarfile.open('exploit.tar', 'w') as tf:
import os
os.mknod('dummy')
"
An attacker builds a tar archive containing a symbolic link with a crafted `linkpath` attribute like C:../../../target.txt. When processed by the vulnerable extraction logic, the security check evaluates one path format while the disk write operation applies the rewritten traversal path, successfully escaping the extraction directory.
Protection:
Upgrade node-tar to version 7.5.11 or higher.
Avoid extracting untrusted archives without validation.
Implement sandboxing for automated package workflows.
Impact:
Arbitrary file overwrite outside intended directories.
Potential code execution via altered system files.
Loss of system integrity and process data.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

