isaacs node-tar

12 known vulnerabilities in isaacs node-tar, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-73566 CVSS 7.5 high node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive…
  • CVE-2026-59875 CVSS 5.3 medium node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath…
  • CVE-2026-59874 CVSS 8.7 high node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a…
  • CVE-2026-59873 CVSS 9.2 critical node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total…
  • CVE-2026-59871 CVSS 7.5 high node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in…
  • CVE-2026-53655 CVSS 6.9 medium node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX…
  • CVE-2026-31802 CVSS 8.2 high node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside…
  • CVE-2026-29786 CVSS 8.2 high node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the…
  • CVE-2026-26960 CVSS 7.1 high node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can…
  • CVE-2026-24842 CVSS 8.2 high node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses…
  • CVE-2026-23950 CVSS 5.9 medium node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete…
  • CVE-2026-23745 CVSS 8.2 high node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries…