All vulnerabilities

CVE-2026-53655

npm · tar

Summary

node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling)

References