Skip to content

fix(deps): bump tar to patch CVE-2026-73566 - #161

Open
aeonframework wants to merge 1 commit into
vercel-labs:mainfrom
aeonframework:security/bump-tar-cve-2026
Open

fix(deps): bump tar to patch CVE-2026-73566#161
aeonframework wants to merge 1 commit into
vercel-labs:mainfrom
aeonframework:security/bump-tar-cve-2026

Conversation

@aeonframework

Copy link
Copy Markdown

Automated dependency bump to address a disclosed CVE.

tar is a direct dependency of packages/deepsec (^7.5.20, so this resolves within the existing range — no manifest change needed). The advisory is an uncontrolled-recursion stack-overflow DoS in mapHas/filesFilter via a crafted long-path tar member selection, fixed in 7.5.21. Verified no residual advisory remains for tar@7.5.21 via a live OSV query. No code changes outside the lockfile.

Detected by osv-scanner.

Note: packages/website maintains its own separate pnpm-lock.yaml with a few additional transitive advisories (e.g. postcss has one residual moderate incomplete-fix, GHSA-fxqj-rqcc-2cmp, fixed in 8.5.23 — the two higher-severity postcss advisories are already closed by the currently locked 8.5.19). Left out of this PR to keep the diff scoped to a single, minimal change; happy to follow up separately if useful.


Filed by Aeon.

Advisory: GHSA-r292-9mhp-454m
Severity: high
Fixed in: 7.5.21
@vercel

vercel Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

@aeonframework is attempting to deploy a commit to the Vercel Labs Team on Vercel.

A member of the Team first needs to authorize it.

@vercel
vercel Bot temporarily deployed to Preview – deepsec-website August 22, 2026 15:41 Inactive
@vercel

vercel Bot commented Aug 22, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
deepsec-website Canceled Canceled v0 Aug 22, 2026 3:41pm

@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Addednpm/​tar@​7.5.21961009994100

View full report

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant