[CVE-2026-23745][node-tar library]Insufficient Link Path Sanitization

January 17, 2026 00:02:51
[CVE-2026-23745][node-tar library]Insufficient Link Path Sanitization
The Daily Cyberspace Information
[CVE-2026-23745][node-tar library]Insufficient Link Path Sanitization

Jan 17 2026 | 00:02:51

/

Show Notes

The node-tar library (Version 7.5.2 or earlier) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass the extraction root restriction, leading to Arbitrary File Overwrite via hardlinks and Symlink Poisoning via absolute symlink targets.

Other Episodes

Episode

January 12, 2026 00:04:19
Episode Cover

The Apache Software Foundation has released Apache HTTP Server 2.4.66.

The Apache Software Foundation has released Apache HTTP Server 2.4.66 to address multiple vulnerabilities in the Apache HTTP Server 2.4 series.

Listen

Episode

January 12, 2026 00:03:44
Episode Cover

Information Disclosure Vulnerability in MongoDB (CVE-2025-14847)

On December 19, 2025, MongoDB disclosed information regarding a vulnerability (CVE-2025-14847) in MongoDB involving information disclosure from uninitialized heap memory. If exploited, an unauthenticated...

Listen

Episode

January 15, 2026 00:00:51
Episode Cover

[CVE-2026-23498]Shopware vulnerability

Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure...

Listen