{"id":"CVE-2026-24909","aliases":["GHSA-gf2c-jwcj-x929"],"url":"https://o3.security/vulnerability/CVE-2026-24909","summary":"vlt Mishandles Path Sanitization for tar","details":"vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.","published":"2026-01-27T22:14:37.716Z","modified":"2026-08-07T11:49:52.628564158Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@vltpkg/tar","fixedVersion":"1.0.0-rc.10"}],"fix":{"url":"https://github.com/vltpkg/vltpkg/pull/1334","label":"vltpkg/vltpkg#1334"},"references":[{"type":"WEB","url":"https://github.com/vltpkg/vltpkg/releases/tag/v1.0.0-rc.10"},{"type":"WEB","url":"https://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attack"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/24xxx/CVE-2026-24909.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24909"},{"type":"FIX","url":"https://github.com/vltpkg/vltpkg/pull/1334"},{"type":"ARTICLE","url":"https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:49:52.628564158Z"}}