THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-73566 (HIGH 7.5) — node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty membe

[NVD] CVE-2026-73566 (HIGH 7.5) — node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty membe

lownvdPublished 2026-08-13

CVE-2026-73566 CVSS: 7.5 HIGH Published: 2026-08-13T18:18:19.250

node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper to walk an archive entry path upward with path.dirname() and no segment cap when tar.t(...) or tar.x(...) receives a non-empty member-selection list. A crafted GNU L or PAX x long-path h

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-73566