[security][CVE-2026-59873] tar in desktop build chain #163
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
New active CVE detected by the
cve-security-triageautomation.CVE-2026-59873tar@7.5.16@electron/node-gyp -> @electron/rebuild -> @electron-forge/* -> apps/desktop7.5.19Project impact
The desktop build and packaging chain resolves a vulnerable
tarrelease while preparing Electron artifacts and rebuild dependencies. The published advisory describes decompression and parse denial of service when extracting attacker-controlled tar input without hard limits. This does not change the deployed web or API runtime, but it does affect developer and CI packaging surfaces for the desktop app.Recommended remediation
tarto7.5.19or laterRun counters
Sources