PT-2025-44446 · Node-Tar · Node-Tar

Published

2025-10-30

·

Updated

2026-03-29

·

CVE-2025-64118

CVSS v4.0

6.1

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:P/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions node-tar versions prior to 7.5.2
Description node-tar is a Tar for Node.js. When using the .t (also known as .list) function with the { sync: true } option to read tar entry contents, uninitialized memory contents may be returned if the tar file is modified on disk to a smaller size during the read operation.
Recommendations Update to version 7.5.2 or later.

Exploit

Fix

Time Of Check To Time Of Use

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-01714
CVE-2025-64118
GHSA-29XP-372Q-XQPH

Affected Products

Node-Tar