CVE-2021-37713 is an arbitrary file creation/overwrite and arbitrary code execution vulnerability in the npm package "tar" (node-tar) affecting versions prior to 4.4.18, 5.0.10, and 6.1.9, specifically on Windows systems. The vulnerability arises from insufficient path sanitization when extracting tar files containing drive letters different from the extraction target or ".." path portions immediately after a drive letter. This high-severity vulnerability (CVSS 8.6) has a local attack vector, low attack complexity, and high potential impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation, no public exploit code, and it is not listed in CISA's KEV catalog, it has garnered significant community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.4.18CPE matchmatch criteria | cpe:2.3:a:npmjs:tar:*:*:*:*:*:node.js:*:* | ||
>= 5.0.0, < 5.0.10CPE matchmatch criteria | cpe:2.3:a:npmjs:tar:*:*:*:*:*:node.js:*:* | ||
>= 6.0.0, < 6.1.9CPE matchmatch criteria | cpe:2.3:a:npmjs:tar:*:*:*:*:*:node.js:*:* | ||
20.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:20.3.3:*:*:*:enterprise:*:*:* | ||
21.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:graalvm:21.2.0:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.