Skip to main content

CVE-2026-24842

CVE Details

Visit the official vulnerability details page for CVE-2026-24842 to learn more.

Initial Publication

01/28/2026

Last Update

02/02/2026

Third Party Dependency

tar

NIST CVE Summary

node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacker to craft a malicious TAR archive that bypasses path traversal protections and creates hardlinks to arbitrary files outside the extraction directory. Version 7.5.7 contains a fix for the issue.

CVE Severity

8.2

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
0.7.1⚠️ Impacted⚠️ Impacted
0.6.6⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.