@turbo/windows-64 is vulnerable to Race Condition (TOCTOU)
63
Medium Risk
Turborepo cache archive and restore logic follows symlinks and is vulnerable to time-of-check/time-of-use races when restoring cached task outputs or writing structured logs. A local attacker who can plant or swap symlinks in the workspace during a run can redirect file reads and writes outside the intended output directory. Experimental OpenTelemetry export also accepted HTTPS endpoints targeting private networks and cloud metadata hosts. The fix uses no-follow opens, race-safe path validation, directory modes only at creation time, and rejects unsafe OTEL endpoint hosts.
You are affected if you are using a version that falls within the vulnerable range.
@turbo/windows-64 is vulnerable to Race Condition (TOCTOU) in versions 2.8.18 - 2.9.14.
Upgrade the @turbo/windows library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant