Medium severity5.9OSV Advisory· Published Jan 27, 2026· Updated Apr 15, 2026
CVE-2026-24909
CVE-2026-24909
Description
vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@vltpkg/tarnpm | < 1.0.0-rc.10 | 1.0.0-rc.10 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-gf2c-jwcj-x929ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-24909ghsaADVISORY
- github.com/vltpkg/vltpkg/commit/ff8d4099a1929772cea2adf131285e90ede6b0ddghsaWEB
- github.com/vltpkg/vltpkg/pull/1334nvdWEB
- github.com/vltpkg/vltpkg/releases/tag/v1.0.0-rc.10nvdWEB
- www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-actnvdWEB
- www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attacknvdWEB
News mentions
0No linked articles in our index yet.