Skip to content

[Security]: @capacitor/cli depends on vulnerable version of node-tar #8308

@pbc-ah

Description

@pbc-ah

Capacitor Version

8

Platforms Affected

  • Android
  • iOS
  • Web

Current Behavior

@capacitor/cli depends on vulnerable version of node-tar

node-tar <=7.5.2 is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization - GHSA-8qq5-rm4j-mr97.

Version that has fixed that vulnerability is 7.5.3.

I doubt this affects things really, but might cause concern among users upon seeing the security vulnerability, and the fix that is recommended by audit fix is ridiculous (downgrade to @capacitor/cli@2.5).

Expected Behavior

No error during update or audit fix.

Additional Information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions