Home

Description

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.

PUBLISHED Reserved 2025-05-19 | Published 2025-06-02 | Updated 2025-11-03 | Assigner GitHub_M




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

< 1.16.5
affected

>= 2.0.0, < 2.1.3
affected

>= 3.0.0, < 3.0.9
affected

References

lists.debian.org/debian-lts-announce/2025/06/msg00012.html

github.com/...tar-fs/security/advisories/GHSA-8cj5-5rvv-wf4v

github.com/...search/security/advisories/GHSA-xrg4-qp5w-2c3w

github.com/...ommit/647447b572bc135c41035e82ca7b894f02b17f0f

cve.org (CVE-2025-48387)

nvd.nist.gov (CVE-2025-48387)

Download JSON