High severity7.5OSV Advisory· Published Apr 30, 2019· Updated Jun 17, 2026
CVE-2018-20834
CVE-2018-20834
Description
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tarnpm | >= 3.0.0, < 4.4.2 | 4.4.2 |
tarnpm | < 2.2.2 | 2.2.2 |
Affected products
3Patches
Vulnerability mechanics
References
8- github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8nvdPatchThird Party AdvisoryWEB
- github.com/npm/node-tar/compare/58a8d43...a5f7779nvdPatchThird Party AdvisoryWEB
- hackerone.com/reports/344595nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-j44m-qm6p-hp7mghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-20834nvdADVISORY
- access.redhat.com/errata/RHSA-2019:1821nvdWEB
- github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395dnvdWEB
- github.com/npm/node-tar/commits/v2.2.2nvdWEB
News mentions
0No linked articles in our index yet.