tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
History

Thu, 25 Sep 2025 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Tar-fs Project
Tar-fs Project tar-fs
Vendors & Products Tar-fs Project
Tar-fs Project tar-fs

Thu, 25 Sep 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

threat_severity

Important


Wed, 24 Sep 2025 17:45:00 +0000

Type Values Removed Values Added
Description tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
Title tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Weaknesses CWE-22
CWE-61
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-09-24T17:43:34.728Z

Updated: 2025-09-24T17:43:34.728Z

Reserved: 2025-09-12T12:36:24.636Z

Link: CVE-2025-59343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-24T18:15:42.297

Modified: 2025-09-26T14:32:53.583

Link: CVE-2025-59343

cve-icon Redhat

Severity : Important

Publid Date: 2025-09-24T17:43:34Z

Links: CVE-2025-59343 - Bugzilla