[security][CVE-2026-59873] tar in desktop build chain #163

Open
opened 2026-08-25 13:20:29 +00:00 by dirtydishes · 0 comments
Owner

New active CVE detected by the cve-security-triage automation.

  • CVE: CVE-2026-59873
  • Component: tar@7.5.16
  • In-repo path: @electron/node-gyp -> @electron/rebuild -> @electron-forge/* -> apps/desktop
  • Severity: Critical (CVSS 9.2)
  • Fixed version: 7.5.19

Project impact

The desktop build and packaging chain resolves a vulnerable tar release while preparing Electron artifacts and rebuild dependencies. The published advisory describes decompression and parse denial of service when extracting attacker-controlled tar input without hard limits. This does not change the deployed web or API runtime, but it does affect developer and CI packaging surfaces for the desktop app.

Recommended remediation

  • Move the dependency set to a release that resolves tar to 7.5.19 or later
  • If upstream Electron tooling lags, add a narrow override and regenerate both root and mirrored Docker lockfiles
  • Re-run the CVE scan after the lockfile change

Run counters

  • unaddressed critical CVEs: 3
  • unaddressed medium/low CVEs: 77
  • unaddressed total CVEs: 95

Sources

New active CVE detected by the `cve-security-triage` automation. - CVE: `CVE-2026-59873` - Component: `tar@7.5.16` - In-repo path: `@electron/node-gyp -> @electron/rebuild -> @electron-forge/* -> apps/desktop` - Severity: Critical (CVSS 9.2) - Fixed version: `7.5.19` Project impact The desktop build and packaging chain resolves a vulnerable `tar` release while preparing Electron artifacts and rebuild dependencies. The published advisory describes decompression and parse denial of service when extracting attacker-controlled tar input without hard limits. This does not change the deployed web or API runtime, but it does affect developer and CI packaging surfaces for the desktop app. Recommended remediation - Move the dependency set to a release that resolves `tar` to `7.5.19` or later - If upstream Electron tooling lags, add a narrow override and regenerate both root and mirrored Docker lockfiles - Re-run the CVE scan after the lockfile change Run counters - unaddressed critical CVEs: 3 - unaddressed medium/low CVEs: 77 - unaddressed total CVEs: 95 Sources - https://github.com/advisories/GHSA-23hp-3jrh-7fpw - https://nvd.nist.gov/vuln/detail/CVE-2026-59873 - https://github.com/isaacs/node-tar/releases/tag/v7.5.19
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
dirtydishes/islandflow#163
No description provided.