SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-18508

MEDIUM · CVSS 4.4 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

GNU tar is vulnerable when using the --one-top-level option, as it allows hardlink targets to escape the designated top-level directory during extraction. This flaw can lead to unauthorized file writes outside the intended boundaries, especially when combined with existing symbolic links in the working directory. Organizations using GNU tar for archive extraction should prioritize addressing this vulnerability to prevent potential data integrity issues and unauthorized access.

CVE
CVE-2026-18508
Severity
MEDIUM
CVSS
4.4
EPSS
0.14%

Original NVD Description

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction.

Related CVEs

Other vulnerabilities affecting the same vendor(s)