Executive brief
The npm tar package is used to extract and manipulate tar archive files across many Node.js applications. On Windows systems, the package's path sanitization logic fails to properly restrict file extraction to the intended directory, allowing an attacker to craft a malicious tar archive that extracts files outside the target location. This could enable arbitrary file overwrites or creation of executable files, potentially leading to code execution or data tampering.
Technical details
A path traversal vulnerability in node-tar's Windows path handling allows extraction of files outside the intended extraction target directory. The root cause is insufficient sanitization of drive-relative paths (e.g., C:some\path) and drive-prefixed directory traversal sequences (e.g., C:../foo). When a tar archive contains an entry with a path that specifies a different drive letter from the extraction target on Windows, the path.resolve() call resolves against the current working directory of that drive rather than the extraction target, bypassing containment checks. Additionally, paths with a drive letter followed immediately by .. (like c:../) were not caught by the existing directory traversal filter. The vulnerability affects Windows systems only. Patches in versions 4.4.18, 5.0.10, and 6.1.9 strip path roots from all paths before resolution and add defense-in-depth checks to skip extraction of entries that would escape the target directory.
Affected products
- npm tar all versions before 4.4.18; 5.0.0 to 5.0.9; 6.0.0 to 6.1.8
Timeline
- 2021-08-31: disclosed: Advisory published
- 2021-08-31: patched: Patches released in versions 4.4.18, 5.0.10, 6.1.9
References
- https://github.com/npm/node-tar/security/advisories/GHSA-5955-9wpr-37jh
- https://github.com/isaacs/node-tar/commit/52b09e309bcae0c741a7eb79a17ef36e7828b946
- https://github.com/isaacs/node-tar/commit/82eac952f7c10765969ed464e549375854b26edc
- https://github.com/isaacs/node-tar/commit/875a37e3ec031186fc6599f6807341f56c584598
- https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf
- https://github.com/npm/node-tar