File tree Expand file tree Collapse file tree
Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -19,3 +19,24 @@ vulnerabilities:
1919 purls :
2020 - " pkg:pypi/wheel@0.45.1"
2121 expired_at : 2026-08-12
22+ - id : CVE-2025-64756
23+ statement : " glob: glob: Command Injection Vulnerability via Malicious Filenames"
24+ purls :
25+ - " pkg:npm/glob@10.4.5"
26+ - " pkg:npm/glob@11.0.3"
27+ expired_at : 2026-08-13
28+ - id : CVE-2026-23745
29+ statement : " node-tar: tar: node-tar: Arbitrary file overwrite and symlink poisoning via unsanitized linkpaths in archives"
30+ purls :
31+ - " pkg:npm/tar@7.5.1"
32+ expired_at : 2026-08-13
33+ - id : CVE-2026-23950
34+ statement : " node-tar: tar: node-tar: Arbitrary file overwrite via Unicode path collision race condition"
35+ purls :
36+ - " pkg:npm/tar@7.5.1"
37+ expired_at : 2026-08-13
38+ - id : CVE-2026-24842
39+ statement : " node-tar: tar: node-tar: Arbitrary file creation via path traversal bypass in hardlink security check"
40+ purls :
41+ - " pkg:npm/tar@7.5.1"
42+ expired_at : 2026-08-13
You can’t perform that action at this time.
0 commit comments