The GitHub security team has identified several high-severity vulnerabilities in npm packages, “tar” and “@npmcli/arborist”, which are used by the npm CLI.
The tar package has an average of 20 million weekly downloads, while arborist is downloaded over 300,000 times each week.
The vulnerabilities affect both Windows and Unix-based users, and if left unresolved, can be exploited by hackers to achieve arbitrary code execution on a system that installs untrusted npm packages.
See also: Copilot: The new AI code generation tool from GitHub and OpenAI

Bug bounty hunters received $14,500 for ZIP slips
Between July and August of this year, security researchers and bug bounty hunters Robert Chen and Philip Papurt discovered arbitrary code execution vulnerabilities in the open source Node.js, tar, and @npmcli/arborist packages.
Upon discovering these vulnerabilities, the researchers privately notified npm through one of GitHub's bug bounty programs.
In further review of the researchers' reports, the GitHub security team found some higher severity vulnerabilities in the aforementioned packages, affecting both Windows and Unix-based systems.
The Node.js tar package remains a key dependency for installers that need to unpack npm packages after installation. The package is also used by thousands of other open source projects and as such receives approximately 20 million downloads every week. The arborist package is a key dependency that is based on the npm CLI and is used to manage node_modules trees.
See also: GitHub bug bounty: Researchers' rewards reach $1.5 million
These ZIP slip vulnerabilities pose a problem for developers who install untrusted npm packages using the npm CLI or using “tar” to extract untrusted packages.
By default, npm packages are shipped as .tar.gz or .tgz files which are ZIP-type files and therefore need to be extracted by the installation tools.
Tools that extract these files should ideally ensure that malicious paths within the file do not end up overwriting existing files, especially sensitive ones, in the filesystem.
But, due to the vulnerabilities listed below, the npm package when extracted could overwrite arbitrary files with the privileges of the user running the npm install command:
The GitHub Security team thanked both Chen and Papurt for their disclosure and awarded them a total of $14,500 for their efforts to keep GitHub secure.
See also: GitHub: Developers will upload videos to their repositories
npm urges users to fix vulnerabilities
npm, which is owned by GitHub, is urging developers to fix these vulnerabilities as soon as possible in a tweet:
Developers should upgrade tar dependency versions to 4.4.19, 5.0.11, or 6.1.10 and upgrade @npmcli/arborist to version 2.8.2 to fix the vulnerabilities.
For npm CLI, versions v6.14.15, v7.21.0 or later contain the fix. Additionally, Node.js version 12, 14, or 16 come with the patched tarball and can be safely upgraded, according to GitHub.
Full details related to these vulnerabilities are available in the detailed GitHub post.
Information source: bleepingcomputer.com
