CVE-2026-29786 is a path traversal vulnerability in node-tar versions before 7.5.10. During normal tar.x() extraction, a crafted drive-relative hardlink target can cause node-tar to create a hardlink pointing outside the intended extraction directory. This bypasses extraction-directory confinement and enables file overwrite outside the extraction working directory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a minimal proof-of-concept for CVE-2026-29786 (claimed Node.js `tar` package symlink/path traversal issue). Structure: (1) README.md describing the vulnerability concept (symlink entry in tar leading to writes outside extraction dir), (2) poc.cjs Node.js script, (3) MIT LICENSE. The PoC script programmatically constructs a pseudo “archive” array with a tar header specifying `type: 'symlink'` and a `linkpath` intended to traverse outside the extraction directory, writes it to `./malicious.tar`, then extracts it into `./test_extract` using `tar.extract`. It then checks for creation of `poc_overwrite.txt` in the current working directory as an indicator of arbitrary file write outside the target directory. No network activity is present; all observables are local file paths and the npm dependency on `tar` (README suggests version 7.5.9).
Repository contains a minimal PoC for CVE-2026-29786 affecting the Node.js 'tar' (node-tar) package. Structure: (1) README.md explains the bug: traversal detection occurs before stripping absolute/drive prefixes in Unpack[STRIPABSOLUTEPATH], allowing a drive-relative link target like 'C:../target.txt' to evade '..' checks and later normalize to '../target.txt'. (2) poc.cjs is the executable PoC: it writes a victim file at ../target.txt, crafts a tar header with a hardlink entry (path 'l', type 'Link') whose linkpath is 'C:../target.txt', saves it as poc.tar, then extracts it with tar.x({cwd, file}). After extraction it writes to './l', demonstrating that the write propagates to the external target via the hardlink, effectively achieving an arbitrary file overwrite outside the extraction directory. No network activity; the exploit is a local/CI supply-chain style vector triggered by extracting an untrusted tar archive.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.