Symlink Attack Vulnerability in Node.js Tar Package
CVE-2015-8860
7.5HIGH
What is CVE-2015-8860?
The tar package for Node.js, prior to version 2.0.0, is vulnerable to a symlink attack. This vulnerability allows remote attackers to manipulate archive files, enabling unauthorized writing to arbitrary files on the targeted system. By exploiting this issue, attackers can achieve unexpected results and potentially compromise the security of applications relying on affected versions of the tar package.