GHSA-5r98-f33j-g8h7
HIGHCVE-2023-37478It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives.
- Affected
- >= 8.0.0, < 8.6.8, < 7.33.4
- Fixed in
- 8.6.8
- Weakness
- CWE-284
- Published
- 2023-08-01
- Source
- github