Executive brief
npm tar is a utility for reading and writing tar archives, commonly used for extracting package dependencies and processing uploaded files. A crafted tar file with an extremely long file path can trigger an uncontrollable recursive function that crashes the Node.js process, causing denial of service to any application that extracts or lists files with member selection filters applied.
Technical details
The vulnerability is an uncontrolled recursion stack-exhaustion flaw in the mapHas helper function used by filesFilter (src/list.ts). When tar.t() or tar.x() is called with a non-empty member-selection list, a filter is installed that recursively walks file paths using path.dirname() with no segment limit. An attacker can craft a tar archive containing a GNU-L or PAX-x long-path header with tens of thousands of "/" segments (up to 1 MiB). The filter invocation occurs inside Parser[CONSUMEHEADER] at src/parse.ts:253, outside the only try/catch block, causing an uncatchable RangeError that terminates the process. A ~188-byte gzip-compressed archive (≈26 KB uncompressed) is sufficient to trigger the crash on both async and streaming consumers.
Affected products
- npm tar <=7.5.20
Timeline
- 2026-07-24: disclosed
- 2026-07-21: patched: Fixed in version 7.5.21