Status
Impact
The tar-fs vulnerability exists in the vscode submodule at /usr/lib/code-server/lib/vscode/node_modules/tar-fs. npm overrides set in the top-level package.json do not apply to the vscode submodule's dependencies because vscode has its own committed package-lock.json from upstream Microsoft repository. The fix requires upstream vscode to update tar-fs to 3.1.1+.
Status