tar
NPM Package
Vulnerability Check
tar for node
tar
Advisory Breakdown
Severity Rating
High severity15 advisories
High severity
Weekly downloads
95,410,072
Total advisories
15
Latest version
7.5.16
License
BlueOak-1.0.0
Known advisories
OSV records for the npm ecosystem
node-tar has a race condition leading to uninitialized memory exposure
node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization
Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction
node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization
node-tar Symlink Path Traversal via Drive-Relative Linkpath
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Denial of service while parsing a tar file due to lack of folders count validation
Symlink Arbitrary File Overwrite in tar
Arbitrary File Overwrite in tar
tar has Hardlink Path Traversal via Drive-Relative Linkpath
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS
Checked Jun 14, 2026, 11:18 PM from npm and OSV.dev
Package metadata
From the npm registry
- Package name
- tar
- Ecosystem
- npm
- Latest version
- 7.5.16
- License
- BlueOak-1.0.0
- Weekly downloads
- 95,410,072
- Repository
- Open repository
Remediation boundary
What RequestGuard does — and doesn't — cover
RequestGuard does not fix npm package vulnerabilities. Dependency remediation happens through package updates, patches, lockfile changes, and maintainer guidance. RequestGuard can help mitigate runtime abuse around exposed web and API flows while remediation is handled separately.
Data from npm registry and OSV.dev · Checked 6/14/2026, 11:18:06 PM