Back to Database
Status published
Medium
CVE-2025-64118
node-tar vulnerable to race condition leading to uninitialized memory exposure
Vulnerability Description
node-tar is a Tar for Node.js. In 7.5.1, using .t (aka .list) with { sync: true } to read tar entry contents returns uninitialized memory contents if tar file was changed on disk to a smaller size while being read. This vulnerability is fixed in 7.5.2.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-64118
Credits & Attribution
No credits recorded in the NVD database.
References
More from isaacs
View All →CVE-2025-64756
glob CLI: Command injection via -c/--cmd executes matches with shell:true
High
7.5
CVE-2024-28863
node-tar vulnerable to denial of service while parsing a tar file due to lack of folders count validation
Medium
6.5
CVE-2018-20834
A vulnerability was found in node-tar before version 4.4.2 (excluding...
High
7.5
Affected Vendor
isaacs
View all reports →Affected Software
node-tar
Vulnerable Versions:
= 7.5.1
Timeline
Official Publish:
October 30th, 2025
Last Modified:
October 30th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
MITRE ATT&CK TTPs
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1574
Hijack Execution Flow
Persistence
T1565
Data Manipulation
Impact
T1499
Endpoint Denial of Service
Impact
T1190
Exploit Public-Facing Application
Initial Access
T1036
Masquerading
Defense Evasion
T1485
Data Destruction
Impact
T1005
Data from Local System
Collection