WhisperX tag archive

#Tar Extraction

This page collects WhisperX intelligence signals tagged #Tar Extraction. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-04-02 17:27:25 · GitHub Issues

1. Kibana Security Flaw: Malicious Tar Archives Can Exploit Hardlink Validation to Write Outside Intended Directory

A newly disclosed vulnerability in Kibana's archive extraction process allows a maliciously crafted tar archive to bypass directory constraints and write files to arbitrary locations on the host filesystem. The flaw, tracked as CVE-2026-26960, resides in the `tar.extract()` function, which fails to properly validate th...