Skip to content

Tar package in base node installed has CVE-2025-64118 #215

@keithboone

Description

@keithboone

Version

v24.11.0

Platform

Linux 5.10.245-241.976.amzn2.x86_64 nodejs/node#1 SMP Tue Oct 21 22:09:08 UTC 2025 x86_64 Linux

Subsystem

tar

What steps will reproduce the bug?

See public reporting on CVE-2025-64118

How often does it reproduce? Is there a required condition?

Every build since yesterday of this base image.

What is the expected behavior? Why is that the expected behavior?

No CVE detected on base node installation.

What do you see instead?

AWS Inspector reports medium CVE: CVE-2025-64118

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions