ID:12318 - Exploit for Race condition in node-tar - CVE-2026-23950

 
Main Vulnerability Database Exploits ID:12318 - Exploit for Race condition in node-tar - CVE-2026-23950

ID:12318 - Exploit for Race condition in node-tar - CVE-2026-23950

Published: January 20, 2026


Vulnerability identifier: #VU121671
Vulnerability risk: Medium
CVE-ID: CVE-2026-23950
CWE-ID: CWE-362
Exploitation vector: Remote access
Vulnerable software:
node-tar

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system.

The vulnerability exists due to a race condition in Path Reservations via Unicode Sharp-S (ß) Collisions on macOS APFS. A remote attacker can trick the victim into using a specially crafted archive to bypass the library's internal concurrency safeguards and perform Symlink Poisoning attacks.


Remediation

Install updates from vendor's website.