t
tar project
Security Risk Profile
27
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 5 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 26, 2019 to present
5
Total CVEs
4
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
7.3
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
27/100
low
Severity Distribution
Critical
0High
4Medium
1Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
1Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
2
Most Affected Products
1. redhat/nodejs-tar8
2. Tar Project Tar Node.js8
3. Oracle GraalVM4
4. npm/tar4
5. Tar Project Tar Rust2
Recent Vulnerabilities
See more →CVE-2026-33056
CVSS 5.1EPSS 0%medium
tar-rs: unpack_in can chmod arbitrary directories by following symlinks
Mar 20, 2026
CVE-2021-38511
CVSS 7.5high
Aug 10, 2021🔧 No Patch
CVE-2021-32804
CVSS 8.2high
Arbitrary File Creation/Overwrite due to insufficient absolute path sanitization
Aug 3, 2021
CVE-2021-32803
CVSS 8.2high
Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning
Aug 3, 2021
CVE-2018-20990
CVSS 7.5high
Aug 26, 2019🔧 No Patch
Monitor tar project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.