All 19 CVE vulnerabilities found in node-tar, with AI-generated Chinese analysis, references, and POCs.
This page aggregates security vulnerabilities associated with the npm package node-tar, specifically focusing on the software product maintained within the Node.js ecosystem. It collects documented defects including path traversal, symlink attacks, and arbitrary code execution flaws recorded across multiple release versions of the library. The data covers advisories published over a multi-year period, reflecting the ongoing history of security patches and bug fixes for this widely used archiving tool. Readers can use this hub to track vendor-issued advisories, understand the specific weakness classes affecting the package, and review the chronological vulnerability history for node-tar. The compilation serves as a reference for developers and security teams who need to audit dependencies, assess risk, and verify that their installations include the latest mitigations. By centralizing these records, the page helps users move beyond isolated CVE lookups to grasp the broader pattern of how security issues have evolved within this particular software artifact.
Vendor: npm
All 19 known CVE vulnerabilities affecting node-tar with full Chinese analysis, references, and POCs where available.