nodejs / nodejs/nodejs-dependency-vuln-assessments

Tar package in base node installed has CVE-2025-64118

Open
#215 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
22
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Version

v24.11.0

Platform
Linux 5.10.245-241.976.amzn2.x86_64 nodejs/node#1 SMP Tue Oct 21 22:09:08 UTC 2025 x86_64 Linux
Subsystem

tar

What steps will reproduce the bug?

See public reporting on CVE-2025-64118

How often does it reproduce? Is there a required condition?

Every build since yesterday of this base image.

What is the expected behavior? Why is that the expected behavior?

No CVE detected on base node installation.

What do you see instead?

AWS Inspector reports medium CVE: CVE-2025-64118

Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the public reporting for CVE-2025-64118 and the base image build producing Node v24.11.0. Identify how the vulnerable tar package enters the base Node installation, then verify a fresh build no longer triggers AWS Inspector for this CVE.

Written by the indexing model from the issue text.

Assessment

Tech stack
node.js
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.