modern-tar is vulnerable to Prototype Pollution
30
Low Risk
Affected versions of this package are vulnerable to prototype pollution during tar header parsing. Crafted archive metadata can inject unexpected properties onto internal objects, potentially corrupting application state. While the impact is limited, exploitation may result in a denial-of-service condition by triggering runtime errors such as TypeError: mapping is not iterable, causing the process to crash.
You are affected if you are using a version which is within vulnerability ranges.
modern-tar is vulnerable to Prototype Pollution in versions 0.4.0 - 0.7.3.
Upgrade the modern-tar library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant