tar (node-tar) < 7.5.7 has a security vulnerability
Author: brendonCreated Jan 30, 2026Updated Jul 11, 2026
Labelstype:bugcomp:node.jsstat:awaiting tensorflower
I use @tensorflow/tfjs-node in a project and it calls for a vulnerable version of tar:
Would it be possible to release a new version with an updated dependency?
CVE-2026-24842
Source: tensorflow/tfjs