# tar@6.2.1 security report (npm)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-04T16:56:11.000Z
- Files reviewed: 26
- Findings: 2 medium, 7 low severity findings
- Report: https://security.togoder.click/npm/tar@6.2.1
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the npm package tar@6.2.1 on Oct 4, 2026. An AI review of 26 source files produced 2 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Preserve paths / path traversal risk

Finding ID: `NPS-9AA8057169C3`

File: `lib/unpack.js:138`

The `preservePaths` option (opt.preservePaths) disables protection against '..' and absolute path entries. When enabled, archives can write files outside the extraction target, enabling arbitrary file write. This is intentional but dangerous if exposed to untrusted archives.

### [medium] Symlink/hardlink creation

Finding ID: `NPS-BBD49C631BCD`

File: `lib/unpack.js:493`

The code creates symlinks and hardlinks based on archive-controlled linkpath values (entry.linkpath). Hardlinks are resolved relative to cwd and symlinks can point anywhere. Combined with path reservation and cache pruning logic, this is a known attack surface for tar extraction (link-based overwrite attacks).

### [low] Environment variable manipulation

Finding ID: `NPS-3F53EBC16FA3`

File: `lib/get-write-flag.js:10`

The code reads `process.env.__FAKE_PLATFORM__` and `global.__FAKE_TESTING_FS__`, which allows overriding the platform detection and the `fs` module. While intended for testing, an attacker could potentially set these globals in a supply-chain attack to alter behavior (e.g., force the use of a malicious `fs` implementation).

### [low] Dynamic module loading via global injection

Finding ID: `NPS-8C7AE96726C1`

File: `lib/get-write-flag.js:12`

The code uses `global.__FAKE_TESTING_FS__` to optionally replace the built-in `fs` module. If an attacker can inject this global (e.g., via another package or prototype pollution), they could supply a malicious `fs` object that intercepts file operations. This is a testing hook but introduces a potential bypass of normal module resolution.

### [low] File System Manipulation

Finding ID: `NPS-C2E2E0AA6423`

File: `lib/mkdir.js`

The code performs recursive directory creation and can optionally chown/chmod/unlink files. This is expected behavior for a mkdir wrapper, not malicious.

### [low] potential_input_validation_issue

Finding ID: `NPS-985C9CF3FFA4`

File: `lib/pax.js`

The parseKVLine function uses parseInt and Buffer.byteLength in a naive line-by-line parser, which may not robustly handle all PAX header inputs, but this is a functional limitation, not a malicious pattern.

### [low] File system manipulation outside package scope

Finding ID: `NPS-BF24D5BADF44`

File: `lib/unpack.js`

The unpacker writes, chmods, chowns, unlinks, and creates directories anywhere under the configured cwd (or absolute paths if preservePaths is set). This is the intended function of a tar extractor, but it is a powerful operation that must be sandboxed by callers.

### [low] Suspicious environment variable usage

Finding ID: `NPS-874D00198CCD`

File: `lib/unpack.js:36`

The code reads process.env.TESTING_TAR_FAKE_PLATFORM to override the platform detection. While this is documented as a testing aid, environment variable-controlled platform switching can be abused in some contexts to alter path handling behavior.

### [low] Privilege-related behavior (chown)

Finding ID: `NPS-474360BA2E22`

File: `lib/unpack.js:301`

The code conditionally calls fs.chown/fchown based on preserveOwner (defaults true when running as root) or explicit uid/gid. If run as root with an untrusted archive, this could allow ownership changes on extracted files.

## Files reviewed

- `lib/get-write-flag.js` (medium): The code contains test hooks that allow overriding platform and fs module via environment variables and globals, which could be abused in a supply-chain attack, but no direct malicious behavior is present.
- `lib/unpack.js` (medium): This appears to be the legitimate node-tar unpacking library; no clear malicious patterns (exfiltration, backdoors, shell execution, obfuscation) were found, though it contains inherently powerful filesystem operations and path-preservation options that warrant care when used with untrusted archives.
- `index.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/create.js` (safe): No malicious patterns detected; the code is a standard tar creation utility with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `lib/extract.js` (safe): No malicious patterns detected
- `lib/header.js` (safe): No malicious patterns detected; the code is a standard tar header encoder/decoder with no network, filesystem, or process manipulation.
- `lib/high-level-opt.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/large-numbers.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/list.js` (safe): No malicious patterns detected; the code is part of the tar package's list functionality and performs expected file listing without any exfiltration, obfuscation, or process spawning.
- `lib/mkdir.js` (safe): No malicious patterns detected; code is a standard mkdirp wrapper for tar extraction with expected filesystem operations.
- `lib/mode-fix.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/normalize-unicode.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/normalize-windows-path.js` (safe): No malicious patterns detected
- `lib/pack.js` (safe): The code is a legitimate tar stream creation library with no malicious patterns detected.
- `lib/parse.js` (safe): No malicious patterns detected; this is a standard tar parser implementation with expected dependencies and no exfiltration, credential harvesting, obfuscation, or process execution.
- `lib/path-reservations.js` (safe): No malicious patterns detected; this is a legitimate path reservation system for an archive unpacking library with no network, filesystem, or process activity.
- `lib/pax.js` (safe): No malicious patterns detected; the code implements PAX tar extended header encoding/decoding without network, credential, process, or filesystem abuse.
- `lib/read-entry.js` (safe): No malicious patterns detected; the code is a standard tar entry parser with no network, filesystem, or process execution risks.
- `lib/replace.js` (safe): No malicious patterns detected
- `lib/strip-absolute-path.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/strip-trailing-slashes.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/types.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/update.js` (safe): No malicious patterns detected; the code is a standard tar update module with expected option validation and filtering logic.
- `lib/warn-mixin.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/winchars.js` (safe): Cleared by Jev triage; no further analysis needed
- `lib/write-entry.js` (safe): No malicious patterns detected; code is a legitimate tar entry writer implementation with standard file system and stream operations.

## Version ranges

None of the 3 scanned versions of tar are flagged high or critical. The latest scanned version, 7.5.22, is medium risk. Only versions we have scanned are listed; unscanned versions between them are not covered.

- 6.2.1 – 7.5.22 (`>=6.2.1 <=7.5.22`): medium (Preserve paths / path traversal risk +1 more)

## Scanned versions

- [7.5.22](https://security.togoder.click/npm/tar@7.5.22): medium, 2026-10-06T14:24:37.000Z
- [7.5.19](https://security.togoder.click/npm/tar@7.5.19): medium, 2026-10-06T14:23:40.000Z
- [6.2.1](https://security.togoder.click/npm/tar@6.2.1): medium, 2026-10-04T16:56:11.000Z

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
