PT-2026-105981 · Crates.Io · Decompress
Published
2026-09-19
·
Updated
2026-09-19
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H |
The tar-family extractors in
decompress (.tar, .tar.gz, .tar.xz,
.tar.bz2, .tar.zst) build each output path from the raw archive entry path
and write to it with no traversal check, so a malicious archive can write files
outside the destination directory, a "tar-slip" / zip-slip path traversal
(CWE-22 / CWE-23).In
src/decompressors/tar common.rs (tar extract):rust
let filepath = entry.path()?; // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
// strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?; // writes anywhere.components().skip(opts.strip) removes a fixed number of leading path
components but leaves interior .. components intact so an entry named
e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside
to. This affects all platforms.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Decompress