Skip to main content

GHSA-R292-9MHP-454M

CVE Details​

Visit the official vulnerability details page for GHSA-R292-9MHP-454M to learn more.

Initial Publication​

07/24/2026

Last Update​

07/24/2026

Third Party Dependency​

tar

NIST CVE Summary​

node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection

CVE Severity​

5.3

Our Official Summary​

Investigation is ongoing to determine how this vulnerability affects our products.

Status​

fixed

Affected Products & Versions​

VersionPaletteAIPaletteAI VerteX
1.2.1⚠️ Impacted⚠️ Impacted

Revision History​

No revisions available.