A vulnerability was found in the decompression function of registry-support. This issue can be triggered by an unauthenticated remote attacker when tricking a user into opening a specially modified .tar archive, leading to the cleanup process following relative paths to overwrite or delete files outside the intended scope.
{ "github_reviewed_at": "2024-02-21T23:18:42Z", "severity": "MODERATE", "nvd_published_at": "2024-02-14T00:15:46Z", "cwe_ids": [ "CWE-23" ], "github_reviewed": true }