Intel

AIKIDO-2026-10275

modern-tar is vulnerable to Prototype Pollution

Prototype Pollution Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 2, 2026

30

Low Risk

This Affects:

JSmodern-tar
0.4.0 - 0.7.3
Fixed in 0.7.4
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to prototype pollution during tar header parsing. Crafted archive metadata can inject unexpected properties onto internal objects, potentially corrupting application state. While the impact is limited, exploitation may result in a denial-of-service condition by triggering runtime errors such as TypeError: mapping is not iterable, causing the process to crash.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges.

Background info

modern-tar is vulnerable to Prototype Pollution in versions 0.4.0 - 0.7.3.

How to fix this

Upgrade the modern-tar library to the patch version.