vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.
https://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attack
https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act