🛡️ CVE-2026-42497 (HIGH): BINGOS Archive::Tar ❤.08 lets attackers create hardlinks outside extraction dirs, risking file overwrite or privilege escalation. No patch yet — avoid untrusted tar files. Details: radar.offseq.com/threat/cve-20… #OffSeq #Vulnerability #Perl #Security
CVE-2026-42497: CWE-59 Improper Link Resolution Before File Access ('Link Following') in BINGOS Archive::Tar
CVE-2026-42497 is a vulnerability in BINGOS Archive::Tar versions before 3. 08 for Perl that allows extraction of hardlinks to attacker-controlled paths outside the intended extraction directory.OffSeq Threat Intelligence (OffSeq)

Füsilier Breitlinger
in reply to • • •@offseq What do you mean, "no patch yet"? (Or "no official patch or remediation guidance is currently available" in your link?) Versions 3.10 and 3.08 of Archive::Tar (released one and four days ago, respectively) are available and contain a fix.
See metacpan.org/dist/Archive-Tar/….
Client Challenge
metacpan.org