Path traversal in node-tar - CVE-2026-26960
Published: February 24, 2026
Vulnerability details
The vulnerability allows a remote user to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences within the tar.extract() function when handling hardlinks inside archives. A remote user can pass a specially crafted archive to the application and read or write files to arbitrary locations on the system.
Affected software
IBM Watson Discovery for IBM Cloud Pak for Data
Jira Service Management Data Center
Confluence Data Center
How to mitigate CVE-2026-26960
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.2
Jira Service Management Data Center - addressed in versions 10.3.18, 11.3.5
Confluence Data Center - addressed in versions 9.2.19, 10.2.10