Skip to content

Conversation

@jonshilton
Copy link

Summary

This PR resolves CVE-2026-23745 - Arbitrary File Overwrite and Symlink Poisoning in the tar package.

Vulnerability Details

Changes

  • Updated yarn.lock to resolve tar@^7.5.3
  • The vulnerable tar is no longer in the dependency tree

Linear Issue

https://linear.app/multiverse-io/issue/SQD-1052/cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file-overwrite-and

@jonshilton jonshilton requested a review from DanielO15 January 27, 2026 11:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant