Description
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-0468 | A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2). |
Github GHSA |
GHSA-j44m-qm6p-hp7m | Arbitrary File Overwrite in tar |
References
History
Wed, 04 Feb 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Isaacs
Isaacs tar |
|
| CPEs | cpe:2.3:a:isaacs:tar:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Node-tar Project
Node-tar Project node-tar |
Isaacs
Isaacs tar |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:12:27.376Z
Reserved: 2019-04-30T00:00:00.000Z
Link: CVE-2018-20834
No data.
Status : Modified
Published: 2019-04-30T19:29:03.327
Modified: 2026-02-04T18:31:45.707
Link: CVE-2018-20834
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA