VDB
KO

package

npm / tar

pkg:npm/tar

HIGH 8.2 npm
GHSA-9r2w-394v-53qc · CVE-2021-37701

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Modified: 3/13/2026

HIGH 8.2 npm
GHSA-qq89-hq3f-393p · CVE-2021-37712

Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links

Modified: 3/13/2026

MEDIUM npm
GHSA-vmf3-w455-68vh · CVE-2026-53655

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

Modified: 6/15/2026