Skip to content

HIGH level security vulnerability in dependency chain: node-tar #114

Description

@mcfoton

TL:DR Bump the used version of unleash-client


CVE-2026-23745
The solution is to bump node-tar to at least 7.5.3
The dependency chain is @unleash/nextjs → unleash-client → make-fetch-happen → cacache
make-fetch-happen 15.0.3 uses cacache 20.0.1 (which dropped tar as a dependency).
Need to update @unleash/nextjs to get the newer make-fetch-happen, which is already used by unleash-client

upd: apologies for opening as bug, this is clearly not a bug 😌

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

bugSomething isn't working

Type

No type

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions