Skip to content
This repository was archived by the owner on Jan 28, 2026. It is now read-only.

fix: CVE-2026-23745 - update tar to ^7.5.3#4

Merged
DanielO15 merged 1 commit intomainfrom
fix/sqd-1052-cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file
Jan 27, 2026
Merged

fix: CVE-2026-23745 - update tar to ^7.5.3#4
DanielO15 merged 1 commit intomainfrom
fix/sqd-1052-cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file

Conversation

@jonshilton
Copy link

Summary

This PR resolves CVE-2026-23745 - Arbitrary File Overwrite and Symlink Poisoning in the tar package.

Vulnerability Details

Changes

  • Updated yarn.lock to resolve tar@^7.5.3
  • The vulnerable tar is no longer in the dependency tree

Linear Issue

https://linear.app/multiverse-io/issue/SQD-1052/cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file-overwrite-and

@jonshilton jonshilton requested a review from DanielO15 January 27, 2026 11:15
@DanielO15 DanielO15 merged commit 898f530 into main Jan 27, 2026
2 checks passed
@DanielO15 DanielO15 deleted the fix/sqd-1052-cve-2026-23745-node-tar-is-vulnerable-to-arbitrary-file branch January 27, 2026 14:21
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants