Skip to content

Fix vulnerability, update Npm-tar and Npm-webpack package versions (AST-138832 AST-138839 AST-138886)#158

Merged
cx-margarita-levitm merged 3 commits intomainfrom
bug/FixVelnerability
Mar 10, 2026
Merged

Fix vulnerability, update Npm-tar and Npm-webpack package versions (AST-138832 AST-138839 AST-138886)#158
cx-margarita-levitm merged 3 commits intomainfrom
bug/FixVelnerability

Conversation

@cx-margarita-levitm
Copy link

@cx-margarita-levitm cx-margarita-levitm commented Mar 3, 2026

Fix
AST-138832
AST-138839
AST-138886

@cx-ben-alvo
Copy link
Collaborator

cx-ben-alvo commented Mar 3, 2026

Logo
Checkmarx One – Scan Summary & Details30c4c147-8394-475f-9456-e0444d73cd19


New Issues (1) Checkmarx found the following issues in this Pull Request
# Severity Issue Source File / Package Checkmarx Insight
1 HIGH CVE-2026-29786 Npm-tar-7.5.9
detailsRecommended version: 7.5.10
Description: node-tar is a full-featured Tar for Node.js. Prior to version 7.5.10, tar can be tricked into creating a hardlink that points outside the extractio...
Attack Vector: LOCAL
Attack Complexity: LOW
Vulnerable Package

Fixed Issues (6) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
HIGH CVE-2026-23745 Npm-tar-7.4.3
HIGH CVE-2026-24842 Npm-tar-7.4.3
HIGH CVE-2026-26960 Npm-tar-7.4.3
MEDIUM CVE-2026-23950 Npm-tar-7.4.3
LOW CVE-2025-68157 Npm-webpack-5.98.0
LOW CVE-2025-68458 Npm-webpack-5.98.0

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

Copy link
Collaborator

@cx-anurag-dalke cx-anurag-dalke left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ok

@cx-margarita-levitm cx-margarita-levitm changed the title fix vulnerability Fix vulnerability, update Npm-tar and Npm-webpack package versions Mar 10, 2026
@cx-margarita-levitm cx-margarita-levitm changed the title Fix vulnerability, update Npm-tar and Npm-webpack package versions Fix vulnerability, update Npm-tar and Npm-webpack package versions (AST-138832 AST-138839 AST-138886) Mar 10, 2026
@cx-margarita-levitm cx-margarita-levitm merged commit 284688d into main Mar 10, 2026
9 checks passed
@cx-margarita-levitm cx-margarita-levitm deleted the bug/FixVelnerability branch March 10, 2026 06:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants