Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Isaacs

First CVE: Apr 30, 2019Active for: 7 yearsTotal CVEs: 13
31.7
VTI Score
Medium

Isaacs maintains a focused set of widely used Node.js utility libraries, primarily tar and glob, that are embedded across countless JavaScript projects and development workflows. The recurring vulnerability exposure centers on path-traversal and link-following conditions alongside resource-handling and CSRF issues, reflecting the file-system and network interaction surface that these foundational utilities present to downstream consumers. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
1.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 79% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Isaacs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 30, 2019
7 years ago
Most Recent CVE
Jul 8, 2026
16 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-59873HIGH
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression
Jul 8, 20267.537NONO
CVE-2026-59874HIGH
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing th
Jul 8, 20267.535NONO
CVE-2026-59871HIGH
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing do
Jul 8, 20267.532NONO
CVE-2026-24842HIGH
node-tar,a Tar for Node.js, contains a vulnerability in versions prior to 7.5.7 where the security check for hardlink entries uses different path resolution semantics than the actu
Jan 28, 20268.230NONO
CVE-2025-64756HIGH
Glob matches files using patterns the shell uses. Starting in version 10.2.0 and prior to versions 10.5.0 and 11.1.0, the glob CLI contains a command injection vulnerability in its
Nov 17, 20257.530NONO
CVE-2026-23745MEDIUM
node-tar is a Tar for Node.js. The node-tar library (<= 7.5.2) fails to sanitize the linkpath of Link (hardlink) and SymbolicLink entries when preservePaths is false (the default s
Jan 16, 20266.128NONO
CVE-2026-53655MEDIUM
node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any
Jun 22, 20265.527NONO
CVE-2026-29786MEDIUM
node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extraction directory by using a drive-rela
Mar 7, 20266.327NONO
CVE-2026-26960HIGH
node-tar is a full-featured Tar for Node.js. When using default options in versions 7.5.7 and below, an attacker-controlled archive can create a hardlink inside the extraction dire
Feb 20, 20267.127NONO
CVE-2026-23950MEDIUM
node-tar,a Tar for Node.js, has a race condition vulnerability in versions up to and including 7.5.3. This is due to an incomplete handling of Unicode path collisions in the `path-
Jan 20, 20265.926NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
46%
54%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (38.5%)
Network8 (61.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None7 (53.8%)
Unknown0 (0.0%)
Required6 (46.2%)
Privileges Required
Low2 (15.4%)
High0 (0.0%)
None11 (84.6%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Isaacs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Isaacs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Isaacs's Products

View all 2 CNAs →

Top CWEs