CVE-2025-59343

Source
https://cve.org/CVERecord?id=CVE-2025-59343
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-59343.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-59343
Aliases
Downstream
Related
Published
2025-09-24T17:43:34.728Z
Modified
2026-05-18T05:58:13.022315233Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Details

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.

Database specific
{
    "cwe_ids": [
        "CWE-22",
        "CWE-61"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59343.json"
}
References

Affected packages

Git / github.com/mafintosh/tar-fs

Affected ranges

Type
GIT
Repo
https://github.com/mafintosh/tar-fs
Events

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-59343.json"