Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-r292-9mhp-454m
  • npm/tar
node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection 24 Jul
  • Fix available
  • Severity - 7.5 (High)
GHSA-w8wr-v893-vjvp
  • npm/tar
node-tar: Process crash via PAX numeric path type confusion 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-23hp-3jrh-7fpw
  • npm/tar
node-tar: Decompression/parse DoS via unlimited input 20 Jul
  • Fix available
  • Severity - 9.2 (Critical)
GHSA-8x88-c5mf-7j5w
  • npm/tar
node-tar: Negative tar entry size causes infinite loop in archive replace 20 Jul
  • Fix available
  • Severity - 8.7 (High)
GHSA-gvwx-54wh-qm9j
  • npm/tar
node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records 20 Jul
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-vmf3-w455-68vh
  • npm/tar
node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) 15 Jun
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-9ppj-qmqm-q256
  • npm/tar
node-tar Symlink Path Traversal via Drive-Relative Linkpath 10 Mar
  • Fix available
  • Severity - 8.2 (High)
GHSA-qffp-2rhf-9h96
  • npm/tar
tar has Hardlink Path Traversal via Drive-Relative Linkpath 05 Mar
  • Fix available
  • Severity - 8.2 (High)
GHSA-83g3-92jg-28cx
  • npm/tar
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction 18 Feb
  • Fix available
  • Severity - 7.1 (High)
GHSA-34x7-hfp2-rc4v
  • npm/tar
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal 28 Jan
  • Fix available
  • Severity - 8.2 (High)
GHSA-gf2c-jwcj-x929
  • npm/@vltpkg/tar
vlt Mishandles Path Sanitization for tar 28 Jan
  • Fix available
  • Severity - 5.9 (Medium)
GHSA-r6q2-hw4h-h46w
  • npm/tar
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS 21 Jan
  • Fix available
  • Severity - 8.8 (High)
GHSA-8qq5-rm4j-mr97
  • npm/tar
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization 16 Jan
  • Fix available
  • Severity - 8.2 (High)
GHSA-29xp-372q-xqph
  • npm/tar
node-tar has a race condition leading to uninitialized memory exposure 30 Oct 2025
  • Fix available
  • Severity - 6.1 (Medium)
GHSA-vj76-c3g6-qr5v
  • npm/tar-fs
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball 24 Sep 2025
  • Fix available
  • Severity - 8.7 (High)
GHSA-8cj5-5rvv-wf4v
  • npm/tar-fs
tar-fs can extract outside the specified dir with a specific tarball 03 Jun 2025
  • Fix available
  • Severity - 8.7 (High)