Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
As with the previous node-tar issues e.g. rhbz#2431082, this was deemed as not exploitable in our products by the upstream (https://github.com/nodejs/nodejs-dependency-vuln-assessments/issues/266#issuecomment-3946106300) and by our investigation, since all links all already filtered in the used configuration. Specifically in this part of the code:https://github.com/npm/pacote/blob/18d36e64a6cc44ac28b7ed2b45e6d2dda4dcf317/lib/fetcher.js#L428-L430. Therefore I'm closing this tickets as "not a bug".