vlt before 1.0.0-rc.10 mishandles path sanitization for tar, leading to path traversal during extraction.Referenceshttps://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attackhttps://github.com/vltpkg/vltpkg/releases/tag/v1.0.0-rc.10https://github.com/vltpkg/vltpkg/pull/1334https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act