All 19 CVE vulnerabilities found in node-tar, with AI-generated Chinese analysis, references, and POCs.
This page catalogs security vulnerabilities identified in node-tar, a popular Node.js package used for working with tar archives, categorized under generic weakness types and tagged for easy navigation. It aggregates data regarding various security flaws, including improper input validation and path traversal issues, covering the period from the package's initial public release through the most recent disclosed incidents. By reviewing this compilation, users can systematically track vendor advisories related to specific versions, gain a deeper understanding of the underlying weakness classes that affect archival processing libraries, and lookup the comprehensive vulnerability history of node-tar to assess risk exposure. The information presented is derived from publicly available security databases and official patch notes, providing a centralized view of the product's security posture over time. This resource is intended for developers, security analysts, and system administrators who require accurate historical data to make informed decisions about dependency management and remediation efforts. It does not include private or unreleased vulnerabilities, focusing solely on verified and disclosed issues. The structure allows for efficient filtering by date, severity, and specific technical characteristics, ensuring that stakeholders can quickly identify relevant entries without sifting through unrelated noise. Maintaining an up-to-date record helps organizations mitigate risks associated with outdated or vulnerable software components in their deployment pipelines.
Vendor: npm
All 19 known CVE vulnerabilities affecting node-tar with full Chinese analysis, references, and POCs where available.