It was discovered that the symlink validation in node-tar-fs, a Node.js module that provides filesystem-like access to tar files, could be bypassed.
https://security-tracker.debian.org/tracker/DSA-6013-1
Continue reading...
https://security-tracker.debian.org/tracker/DSA-6013-1
Continue reading...

