Known Vulnerable Dependency: tar==7.5.9 — 8 advisory(ies): CVE-2026-59873 (node-tar: Decompression/parse DoS via unlimited input); CVE-2026-59874 (node-tar: Negative tar entry size causes infinite loop in archive replace); CVE-2026-31802 (node-tar Symlink Path Traversal via Drive-Relative Linkpath) +5 more
Critical
- Category
- Supply Chain
- Confidence
- 91% confidence
- Finding
- The lockfile includes tar 7.5.9 through onnxruntime-node, and the listed advisories include denial-of-service and path traversal issues in archive handling. This is not the skill's primary business logic, but install-time or runtime archive extraction in native dependency tooling increases supply-chain risk, especially for builds or environments that fetch and unpack artifacts automatically.
