REDHAT-BUG-2445476: High severity node-tar vulnerability
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables file overwrite outside cwd during normal tar.x() extraction. This issue has been patched in version 7.5.10.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
node-tarto a version that resolves this vulnerability.Fixed in 7.5.10
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2445476?
The severity of REDHAT-BUG-2445476 is high, rated at 7.
How do I fix REDHAT-BUG-2445476?
To fix REDHAT-BUG-2445476, upgrade node-tar to version 7.5.10 or later.
What vulnerabilities does REDHAT-BUG-2445476 expose?
REDHAT-BUG-2445476 exposes the risk of file overwriting outside the current working directory during tar extraction.
Which software is affected by REDHAT-BUG-2445476?
The affected software by REDHAT-BUG-2445476 is node-tar.
When was REDHAT-BUG-2445476 published?
REDHAT-BUG-2445476 was published on March 7, 2026.