Home
MEDIUM: 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:NDefault status
unaffected
Any version before 1.0.0-rc.10
affected
Description
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
Problem types
CWE-23 Relative Path Traversal
Product status
Any version before 1.0.0-rc.10
References
www.scworld.com/...bugs-lead-to-fears-of-supply-chain-attack
github.com/vltpkg/vltpkg/releases/tag/v1.0.0-rc.10
github.com/vltpkg/vltpkg/pull/1334
www.koi.ai/...o-days-in-js-package-managers-but-npm-wont-act