It is possible to craft an OCI tar archive that, when stereoscope attempts to unarchive the contents, will result in writing to paths outside of the unarchive temporary directory.
{
"url": "https://pkg.go.dev/vuln/GO-2024-2490",
"review_status": "REVIEWED"
}