Vulnerabilities > TAR Project > TAR > 0.1.2

DATE CVE VULNERABILITY TITLE RISK
2021-08-03 CVE-2021-32803 Link Following vulnerability in multiple products
The npm package "tar" (aka node-tar) before versions 6.1.2, 5.0.7, 4.4.15, and 3.2.3 has an arbitrary File Creation/Overwrite vulnerability via insufficient symlink protection.
5.8
2021-08-03 CVE-2021-32804 Path Traversal vulnerability in multiple products
The npm package "tar" (aka node-tar) before versions 6.1.1, 5.0.6, 4.4.14, and 3.3.2 has a arbitrary File Creation/Overwrite vulnerability due to insufficient absolute path sanitization.
5.8