node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.
References
| Link | Resource |
|---|---|
| https://github.com/isaacs/node-tar/commit/e02a4e9e013c4be95302e2eb2047a942b883c27b | Patch |
| https://github.com/isaacs/node-tar/releases/tag/v7.5.18 | Release Notes |
| https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp | Exploit Vendor Advisory |
| https://github.com/isaacs/node-tar/security/advisories/GHSA-w8wr-v893-vjvp | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-07-08 16:16
Updated : 2026-07-10 19:02
NVD link : CVE-2026-59871
Mitre link : CVE-2026-59871
CVE.ORG link : CVE-2026-59871
JSON object : View
Products Affected
isaacs
- tar
CWE
CWE-704
Incorrect Type Conversion or Cast
