
node-tar hardlink escape enables arbitrary file read/write
A newly published CVE for the npm `tar` package describes a High-severity hardlink escape during archive extraction.
VulnerabilityNode.jsDependency Security
1 min20 Feb 2026
Application security news, updated daily (if there is any news to share).
Content is AI-assisted and reviewed by our team, but issues may be missed and best practices evolve rapidly, send corrections to [email protected]. Always consult official documentation and validate key implementation decisions before making design or security choices.