tar
npm21 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting tarpage 1 of 1
- CVE-2015-8860HIGHCVSS 7.5EG 7.5fixed in 2.0.02017-01-23
The tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive.
- CVE-2018-20834HIGHCVSS 7.5EG 7.5fixed in 4.4.2 or 2.2.2, by version range2019-04-30
A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with…
- CVE-2021-32803HIGHCVSS 8.2EG 8.2fixed in 3.2.3, 4.4.15, 5.0.7 or 6.1.2, by version range2021-08-03
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection. `node-tar` aims to guarantee that any file whose location woul…
- CVE-2021-32804HIGHCVSS 8.2EG 8.2fixed in 3.2.2, 4.4.14, 5.0.6 or 6.1.1, by version range2021-08-03
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization. node-tar aims to prevent extraction of absolute file…
- CVE-2021-37701HIGHCVSS 8.2EG 8.2fixed in 4.4.16, 5.0.8 or 6.1.7, by version range2021-08-31
The npm package "tar" (aka node-tar) before versions 4.4.16, 5.0.8, and 6.1.7 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified by…
- CVE-2021-37712HIGHCVSS 8.2EG 8.2fixed in 4.4.18, 5.0.10 or 6.1.9, by version range2021-08-31
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be modified b…
- CVE-2021-37713HIGHCVSS 8.2EG 8.2fixed in 4.4.18, 5.0.10 or 6.1.9, by version range2021-08-31
The npm package "tar" (aka node-tar) before versions 4.4.18, 5.0.10, and 6.1.9 has an arbitrary file creation/overwrite and arbitrary code execution vulnerability. node-tar aims to guarantee that any file whose location would be outside of…
- CVE-2024-28863MEDIUMCVSS 6.5EG 6.5fixed in 6.2.12024-03-21
node-tar is a Tar for Node.js. node-tar prior to version 6.2.1 has no limit on the number of sub-folders created in the folder creation process. An attacker who generates a large number of sub-folders can consume memory on the system runni…
- CVE-2025-64118MEDIUMCVSS 6.1EG 6.1fixed in 7.5.22025-10-30
vulnerable: 7.5.1
node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fi…
- CVE-2026-23745MEDIUMCVSS 6.1EG 6.1fixed in 7.5.32026-01-16
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default secure behavior). This allows malicious archives to bypass t…
- CVE-2026-23950MEDIUMCVSS 5.9EG 5.9fixed in 7.5.42026-01-20
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-reservations` system. On case-insensitive or normalization-…
- CVE-2026-24842HIGHCVSS 8.2EG 8.2fixed in 7.5.72026-01-28
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actual hardlink creation logic. This mismatch allows an attacke…
- CVE-2026-26960HIGHCVSS 7.1EG 7.1fixed in 7.5.82026-02-20
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction directory that points to a file outside the extraction root, en…
- CVE-2026-29786MEDIUMCVSS 6.3EG 6.3fixed in 7.5.102026-03-07
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-relative link target such as C:../target.txt, which enables fil…
- CVE-2026-31802MEDIUMCVSS 5.5EG 5.5fixed in 7.5.112026-03-09
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.11, tar (npm) can be tricked into creating a symlink that points outside the extraction directory by using a drive-relative symlink target such as C:../../../target.txt, whi…
- CVE-2026-53655MEDIUMCVSS 5.5EG 5.5fixed in 7.5.162026-06-15
node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU…
- CVE-2026-59871HIGHCVSS 7.5EG 7.5fixed in 7.5.182026-07-08
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.p…
- CVE-2026-59873HIGHCVSS 7.5EG 7.5fixed in 7.5.192026-07-08
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.t…
- CVE-2026-59874HIGHCVSS 7.5EG 7.5fixed in 7.5.182026-07-08
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly pars…
- CVE-2026-59875MEDIUMCVSS 5.3EG 5.3fixed in 7.5.172026-07-08
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and termin…
- CVE-2026-73566HIGHCVSS 7.5EG 7.5fixed in 7.5.212026-08-13
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...)…
Check whether tar is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for tar CVEs against the assets you own.
Book a Demo →