Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-62236.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-62236
Upstream
Published
2025-06-02T20:15:22Z
Modified
2026-04-01T05:20:01.935626Z
Summary
CVE-2025-48387 affecting package reaper for versions less than 3.1.1-19
Details

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.

References

Affected packages

Azure Linux:2 / reaper

Package

Name
reaper
Purl
pkg:rpm/azure-linux/reaper

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.1.1-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-62236.json"