Skip to content

Security: Update tar-fs to fix path traversal vulnerability (CVE-2024-12905) #14

@jmaddington

Description

@jmaddington

Description

The tar-fs package has a high severity path traversal vulnerability (CVE-2024-12905) that could result in unauthorized file writes or overwrites outside the intended extraction directory.

Details

Proposed Solution

Add an override/resolution for tar-fs to ensure version 2.1.2 or higher is used throughout the dependency tree:

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions