Skip to content

CVE-2026-24842 tar version 7.5.4 #8945

@huakaibird

Description

@huakaibird

Is there an existing issue for this?

  • I have searched the existing issues

This issue exists in the latest npm version

  • I am using the latest npm

Current Behavior

The npm tar 7.5.4 has a high CVE (reported by our security scanning tool)
CVE-2026-24842

CVE-2026-24842

tar 7.5.7 has the issue fixed, when npm would have a new release to fix this?

Environment

  • npm: 11.8.0
  • Node.js:
  • OS Name:
  • System Model Name:
  • npm config:
; copy and paste output from `npm config ls` here

Metadata

Metadata

Assignees

No one assigned

    Labels

    Bugthing that needs fixingNeeds Triageneeds review for next steps

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions