SCA: security update for compressing (GHSA-cc8f-xg8v-72m3)

high Tenable Self-Hosted Container Security Plugin ID 437476

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior,
Compressing extracts TAR archives while restoring symbolic links without validating their targets. By
embedding symlinks that resolve outside the intended extraction directory, an attacker can cause
subsequent file entries to be written to arbitrary locations on the host file system. Depending on the
extractor’s handling of existing files, this behavior may allow overwriting sensitive files or creating
new files in security-critical locations. This issue has been patched in versions 1.10.4 and 2.0.1.
(CVE-2026-24884)

See Also

https://github.com/advisories/GHSA-cc8f-xg8v-72m3

Plugin Details

Severity: High

ID: 437476

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 2/3/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-24884

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/3/2026

Vulnerability Publication Date: 2/3/2026

Reference Information

CVE: CVE-2026-24884

cwe: CWE-59