Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

isaacs — Vulnerabilities & Security Advisories 19

Browse all 19 CVE security advisories affecting isaacs. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Isaacs serves as a middleware component facilitating data integration and API connectivity between enterprise systems. Historically, it has been susceptible to multiple remote code execution vulnerabilities, cross-site scripting flaws, and privilege escalation issues, accounting for its 13 recorded CVEs. The platform's complex architecture and extensive third-party integrations have created attack surfaces where improper input validation and insecure deserialization have been recurrent problems. While no major public security incidents have been widely documented, the consistent pattern of vulnerabilities across multiple versions suggests ongoing challenges in secure coding practices and comprehensive testing protocols for this integration middleware.

Found 14 results / 19Clear Filters
CVE IDTitleCVSSSeverityPublished
CVE-2026-73566 node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection — node-tarCWE-400 7.5 High2026-08-13
CVE-2026-59871 node-tar: Process crash via PAX numeric path type confusion — node-tarCWE-704 5.3 Medium2026-07-08
CVE-2026-59874 node-tar: Negative tar entry size causes infinite loop in archive replace — node-tarCWE-835--2026-07-08
CVE-2026-59873 node-tar: Decompression/parse DoS via unlimited input — node-tarCWE-770--2026-07-08
CVE-2026-59875 node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records — node-tarCWE-248 5.3 Medium2026-07-08
CVE-2026-53655 node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) — node-tarCWE-436--2026-06-22
CVE-2026-31802 node-tar Symlink Path Traversal via Drive-Relative Linkpath — node-tarCWE-22 7.5AIHighAI2026-03-09
CVE-2026-29786 node-tar: Hardlink Path Traversal via Drive-Relative Linkpath — node-tarCWE-22 7.5 -2026-03-07
CVE-2026-26960 node-tar has Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in Extraction — node-tarCWE-22 7.1 High2026-02-20
CVE-2026-24842 node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal — node-tarCWE-22 8.2 High2026-01-28
CVE-2026-23950 node-tar has Race Condition in Path Reservations via Unicode Ligature Collisions on macOS APFS — node-tarCWE-176 8.8 High2026-01-20
CVE-2026-23745 node-tar Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization — node-tarCWE-22 8.2 High2026-01-16
CVE-2025-64118 node-tar vulnerable to race condition leading to uninitialized memory exposure — node-tarCWE-362 5.3AIMediumAI2025-10-30
CVE-2024-28863 node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation — node-tarCWE-400 6.5 Medium2024-03-21

This page lists every published CVE security advisory associated with isaacs. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.