MEDIUM5.9
GHSA-gf2c-jwcj-x929
vlt Mishandles Path Sanitization for tar
Quick fix
GHSA-gf2c-jwcj-x929 — @vltpkg/tar: upgrade to the fixed version with the command below.
npm install @vltpkg/tar@1.0.0-rc.10Details
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-24909[ADVISORY]
- https://github.com/vltpkg/vltpkg/pull/1334[WEB]
- https://github.com/vltpkg/vltpkg/commit/ff8d4099a1929772cea2adf131285e90ede6b0dd[WEB]
- https://github.com/vltpkg/vltpkg[PACKAGE]
- https://github.com/vltpkg/vltpkg/releases/tag/v1.0.0-rc.10[WEB]
- https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act[WEB]
- https://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attack[WEB]