Skip to main content
Version: v1.2.x

GHSA-R292-9MHP-454M

CVE Details

Visit the official vulnerability details page for GHSA-R292-9MHP-454M to learn more.

Initial Publication

07/24/2026

Last Update

07/24/2026

Third Party Dependency

tar

NIST CVE Summary

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

CVE Severity

5.3

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

fixed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.2.0⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.