From 58487b6d78c339804cb56e581c794ca8cfa6eaa6 Mon Sep 17 00:00:00 2001 From: Jonathan Addington Date: Mon, 31 Mar 2025 13:54:23 -0400 Subject: [PATCH] Fix tar-fs path traversal vulnerability (CVE-2024-12905) by adding override for version 2.1.2 --- package.json | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/package.json b/package.json index ccea027..20454a9 100644 --- a/package.json +++ b/package.json @@ -26,7 +26,8 @@ "ws": "^7.5.10", "nth-check": "^2.0.1", "body-parser": "^1.20.3", - "path-to-regexp": "^0.1.12" + "path-to-regexp": "^0.1.12", + "tar-fs": "^2.1.2" }, "resolutions": { "canvas": "2.9.3", @@ -39,7 +40,8 @@ "ws": "^7.5.10", "nth-check": "^2.0.1", "body-parser": "^1.20.3", - "path-to-regexp": "^0.1.12" + "path-to-regexp": "^0.1.12", + "tar-fs": "^2.1.2" }, "dependencies": { "bunyan": "^1.8.12",