CVE-2026-59875: Isaacs Node-Tar
Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.
Affected products
- Isaacs Node-Tar: before 7.5.17 (fixed in 7.5.17)
Published 2026-07-08. Last modified 2026-07-10.