Isaacs maintains a focused set of widely used Node.js utility libraries, primarily tar and glob, that are embedded across countless JavaScript projects and development workflows. The recurring vulnerability exposure centers on path-traversal and link-following conditions alongside resource-handling and CSRF issues, reflecting the file-system and network interaction surface that these foundational utilities present to downstream consumers. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Isaacs over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-59873HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression | Jul 8, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-59874HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing th | Jul 8, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-59871HIGH node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing do | Jul 8, 2026 | 7.5 | 32 | NO | NO |
CVE-2026-24842HIGH node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actu | Jan 28, 2026 | 8.2 | 30 | NO | NO |
CVE-2025-64756HIGH Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its | Nov 17, 2025 | 7.5 | 30 | NO | NO |
CVE-2026-23745MEDIUM node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default s | Jan 16, 2026 | 6.1 | 28 | NO | NO |
CVE-2026-53655MEDIUM node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any | Jun 22, 2026 | 5.5 | 27 | NO | NO |
CVE-2026-29786MEDIUM node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-rela | Mar 7, 2026 | 6.3 | 27 | NO | NO |
CVE-2026-26960HIGH node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction dire | Feb 20, 2026 | 7.1 | 27 | NO | NO |
CVE-2026-23950MEDIUM node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path- | Jan 20, 2026 | 5.9 | 26 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Isaacs.
Media articles that mention a CVE ID that affects a product developed by Isaacs — matched by CVE ID, not by vendor name.