/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-3mpv-3fv5-86j9

Published

Last updated

https://images.chainguard.dev/security/CGA-3mpv-3fv5-86j9
Package

npm

RepositoryWolfi
Latest Update
Not affected
Aliases
  • CVE-2025-64118
  • GHSA-29xp-372q-xqph

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-64118

Updates

Status

Not affected

Justification

Vulnerable code not in execute path

Impact

npm does not utilize the affected code path. For more details, refer to the upstream discussions: https://github.com/nodejs/node/pull/60430#issuecomment-3455536702 and https://github.com/nodejs/node/pull/60012#issuecomment-3452094442

Status

Pending upstream fix

Impact

Since this package relies on upstream artifacts, the vulnerability must be remediated upstream by updating tar to version 7.5.2 or later.

Status

Under investigation


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing