Skip to content

chore(deps): upgrade tar to 7.5.7 to address CVE-2026-24842 - #3375

Merged
gengjiawen merged 1 commit into
nodejs:mainfrom
gengjiawen:deps/tar-7.5.7
Sep 30, 2026
Merged

gengjiawen merged 1 commit into
nodejs:mainfrom
gengjiawen:deps/tar-7.5.7

Conversation

@gengjiawen

Copy link
Copy Markdown
Member
Checklist
  • npm install and npm run lint pass. npm test is 108 passing / 6 failing locally — all 6 are test-download.js cases that bind a local HTTP server and fail with ECONNREFUSED 127.0.0.1:<port> in my sandboxed environment, unrelated to this change. CI covers them.
  • commit message follows commit guidelines
Description of change

tar below 7.5.7 is affected by GHSA-34x7-hfp2-rc4v / CVE-2026-24842 (High, CVSS 8.2): the security check for hardlink entries and the hardlink creation itself resolve paths with different semantics, so a crafted archive can place a hardlink outside the extraction directory.

node-gyp still declares "tar": "^7.5.4". In practice a fresh install already resolves to a patched tar (7.5.22 at time of writing), so this is not an exploitable path in node-gyp itself — but the declared floor is what npm audit and lockfile-pinned consumers report against, which is what #3284 asks for. Bumped to the exact patched version, matching what #3271 did for CVE-2026-23950.

For the record, #3284's thread also suggests bumping make-fetch-happen so a newer cacache drops its vulnerable tar. That transitive path is already gone — make-fetch-happen was replaced with built-in fetch in #3302 (v12.3.0). This PR covers the remaining direct dependency, which is what the reporter was actually asking about.

Fixes #3284

tar below 7.5.7 is affected by GHSA-34x7-hfp2-rc4v (CVE-2026-24842), a
hardlink path traversal: the security check for hardlink entries and the
hardlink creation itself resolve paths with different semantics, so a
crafted archive can escape the extraction directory.

The declared range was still ^7.5.4. A fresh install already resolves to
a patched tar, but the floor is what audit tooling and lockfile-pinned
consumers report against, so raise it to the patched version.

Refs: nodejs#3284
@gengjiawen
gengjiawen merged commit 79048c9 into nodejs:main Sep 30, 2026
88 of 93 checks passed
@gengjiawen
gengjiawen deleted the deps/tar-7.5.7 branch September 30, 2026 04:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CVE-2026-24842 - dependency update request for node-tar

2 participants