The Daily Cyberspace Information

[CVE-2026-23745][node-tar library]Insufficient Link Path Sanitization


Listen Later

The node-tar library (Version 7.5.2 or earlier) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets.

...more
View all episodesView all episodes
Download on the App Store

The Daily Cyberspace InformationBy zeotech