GHSA-j44m-qm6p-hp7m · Severity: high · Ecosystem: npm — Arbitrary File Overwrite in tar
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).
Conclusion & alert: CVE-2018-20834 is rated High Exploit Risk (77.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 3.15%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.40% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.75% | 3.15% | +2.40% |
| 2 | 2026-02-13 | 0.77% | 0.75% | -0.02% |
| 3 | 2026-01-28 | — | 0.77% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.0 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 6.4 | 2.0 | MEDIUM |
|
10.0 | 4.9 | [email protected] |
GHSA-j44m-qm6p-hp7m · Severity: high · Ecosystem: npm — Arbitrary File Overwrite in tar
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2018-20834: 1 source package rows (tar); 33 state rows across 6 repos (3.19-main, 3.20-main, 3.21-main, 3.22-main, 3.23-main, edge-main); fixed 33, open 0. | https://security.alpinelinux.org/vuln/CVE-2018-20834 |
debian
|
not yet assigned | CVE-2018-20834 not yet assigned priority: Debian including 1 source packages (node-tar), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2018-20834 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2018-20834 |
ubuntu
|
medium | CVE-2018-20834 medium priority: Ubuntu including 1 source packages (node-tar), 6 status rows across 6 suites (bionic, cosmic, disco, trusty, upstream, xenial): not-affected 5, released 1. | https://ubuntu.com/security/CVE-2018-20834 |
| URL | Tags |
|---|---|
| https://access.redhat.com/errata/RHSA-2019:1821 | |
| https://github.com/npm/node-tar/commit/7ecef07da6a9e72cc0c4d0c9c6a8e85b6b52395d | |
| https://github.com/npm/node-tar/commit/b0c58433c22f5e7fe8b1c76373f27e3f81dcd4c8 | Patch Third Party Advisory |
| https://github.com/npm/node-tar/commits/v2.2.2 | |
| https://github.com/npm/node-tar/compare/58a8d43...a5f7779 | Patch Third Party Advisory |
| https://hackerone.com/reports/344595 | Exploit Third Party Advisory |
| https://nvd.nist.gov/vuln/detail/CVE-2018-20834 |