npm vulnerability intelligence

tar NPM Package
Vulnerability Check

tar for node

High severity BlueOak-1.0.0 v7.5.16
Vulnerability Analysis OSV Live

tar

v7.5.16 · BlueOak-1.0.0 · 95,410,072 dl/wk

Advisory Breakdown

Critical 0
High 13
Moderate 2
Low 0

Severity Rating

High severity

15 advisories

High severity

Weekly downloads

95,410,072

Total advisories

15

Latest version

7.5.16

License

BlueOak-1.0.0

Known advisories

OSV records for the npm ecosystem

15
GHSA-29xp-372q-xqph CVE-2025-64118 moderate

node-tar has a race condition leading to uninitialized memory exposure

Affected: >=7.5.1 <7.5.2 Fixed in: 7.5.2 Updated Feb 4, 2026
View source
GHSA-34x7-hfp2-rc4v CVE-2026-24842 high

node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal

Affected: >=0 <7.5.7 Fixed in: 7.5.7 Updated Feb 4, 2026
View source
GHSA-3jfq-g458-7qm9 CVE-2021-32804 high

Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization

Affected: >=0 <3.2.2, >=4.0.0 <4.4.14, >=5.0.0 <5.0.6, >=6.0.0 <6.1.1 Fixed in: 3.2.2, 4.4.14, 5.0.6, 6.1.1 Updated Mar 13, 2026
View source
GHSA-5955-9wpr-37jh CVE-2021-37713 high

Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization

Affected: >=0 <4.4.18, >=5.0.0 <5.0.10, >=6.0.0 <6.1.9 Fixed in: 4.4.18, 5.0.10, 6.1.9 Updated Mar 13, 2026
View source
GHSA-83g3-92jg-28cx CVE-2026-26960 high

Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction

Affected: >=0 <7.5.8 Fixed in: 7.5.8 Updated Feb 20, 2026
View source
GHSA-8qq5-rm4j-mr97 CVE-2026-23745 high

node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization

Affected: >=0 <7.5.3 Fixed in: 7.5.3 Updated Feb 22, 2026
View source
GHSA-9ppj-qmqm-q256 CVE-2026-31802 high

node-tar Symlink Path Traversal via Drive-Relative Linkpath

Affected: >=0 <7.5.11 Fixed in: 7.5.11 Updated Mar 13, 2026
View source
GHSA-9r2w-394v-53qc CVE-2021-37701 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Affected: >=3.0.0 <4.4.16, >=5.0.0 <5.0.8, >=6.0.0 <6.1.7 Fixed in: 4.4.16, 5.0.8, 6.1.7 Updated Mar 13, 2026
View source
GHSA-f5x3-32g6-xq36 CVE-2024-28863 moderate

Denial of service while parsing a tar file due to lack of folders count validation

Affected: >=0 <6.2.1 Fixed in: 6.2.1 Updated Feb 4, 2026
View source
GHSA-gfjr-3jmm-4g9v CVE-2015-8860 high

Symlink Arbitrary File Overwrite in tar

Affected: >=0 <2.0.0 Fixed in: 2.0.0 Updated Nov 8, 2023
View source
GHSA-j44m-qm6p-hp7m CVE-2018-20834 high

Arbitrary File Overwrite in tar

Affected: >=3.0.0 <4.4.2, >=0 <2.2.2 Fixed in: 4.4.2, 2.2.2 Updated Nov 29, 2023
View source
GHSA-qffp-2rhf-9h96 CVE-2026-29786 high

tar has Hardlink Path Traversal via Drive-Relative Linkpath

Affected: >=0 <7.5.10 Fixed in: 7.5.10 Updated Mar 10, 2026
View source
GHSA-qq89-hq3f-393p CVE-2021-37712 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Affected: >=3.0.0 <4.4.18, >=5.0.0 <5.0.10, >=6.0.0 <6.1.9 Fixed in: 4.4.18, 5.0.10, 6.1.9 Updated Mar 13, 2026
View source
GHSA-r628-mhmh-qjhw CVE-2021-32803 high

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning

Affected: >=3.0.0 <3.2.3, >=4.0.0 <4.4.15, >=5.0.0 <5.0.7, >=6.0.0 <6.1.2 Fixed in: 3.2.3, 4.4.15, 5.0.7, 6.1.2 Updated Mar 13, 2026
View source
GHSA-r6q2-hw4h-h46w CVE-2026-23950 high

Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS

Affected: >=0 <7.5.4 Fixed in: 7.5.4 Updated Mar 16, 2026
View source

Checked Jun 14, 2026, 11:18 PM from npm and OSV.dev

Package metadata

From the npm registry

Package name
tar
Ecosystem
npm
Latest version
7.5.16
License
BlueOak-1.0.0
Weekly downloads
95,410,072

Remediation boundary

What RequestGuard does — and doesn't — cover

RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.

Signup flows
Login attempts
API traffic

Data from npm registry and OSV.dev · Checked 6/14/2026, 11:18:06 PM