PT-2026-105981 · Crates.Io · Decompress

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz, .tar.bz2, .tar.zst) build each output path from the raw archive entry path and write to it with no traversal check, so a malicious archive can write files outside the destination directory, a "tar-slip" / zip-slip path traversal (CWE-22 / CWE-23).
In src/decompressors/tar common.rs (tar extract):
rust
let filepath = entry.path()?;                  // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
                   // strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?;          // writes anywhere
.components().skip(opts.strip) removes a fixed number of leading path components but leaves interior .. components intact so an entry named e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside to. This affects all platforms.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

RUSTSEC-2026-0328

Affected Products

Decompress