PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.
-
Updated
Mar 14, 2026 - JavaScript
PoC and write-up for CVE-2026-31802, a symlink path traversal vulnerability in npm tar enabling arbitrary file overwrite outside the extraction directory.
Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.
Add a description, image, and links to the cve-2026-31802 topic page so that developers can more easily learn about it.
To associate your repository with the cve-2026-31802 topic, visit your repo's landing page and select "manage topics."