nodejs / nodejs/nodejs-dependency-vuln-assessments
Tar package in base node installed has CVE-2025-64118
Open
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 22
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
Version
v24.11.0
Platform
Linux 5.10.245-241.976.amzn2.x86_64 nodejs/node#1 SMP Tue Oct 21 22:09:08 UTC 2025 x86_64 Linux
Subsystem
tar
What steps will reproduce the bug?
See public reporting on CVE-2025-64118
How often does it reproduce? Is there a required condition?
Every build since yesterday of this base image.
What is the expected behavior? Why is that the expected behavior?
No CVE detected on base node installation.
What do you see instead?
AWS Inspector reports medium CVE: CVE-2025-64118
Additional information
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with the public reporting for CVE-2025-64118 and the base image build producing Node v24.11.0. Identify how the vulnerable tar package enters the base Node installation, then verify a fresh build no longer triggers AWS Inspector for this CVE.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- node.js
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 35/100