Executive brief
tar-fs is a Node.js library used to extract and package tar archives. A symlink validation weakness allows attackers to bypass security checks when extracting specially crafted tar files to a predictable directory, potentially leading to unauthorized file writes or directory traversal attacks. This could allow an attacker to write files outside the intended extraction location.
Technical details
tar-fs contains a symlink validation bypass (CWE-22: Path Traversal, CWE-61: Symlink Following) in versions 3.1.0 and earlier, 2.1.3 and earlier, and 1.16.5 and earlier. An attacker can craft a specific tarball that, when extracted to a predictable destination directory, bypasses symlink validation controls. The attack requires control over the tarball content and knowledge of the extraction destination path, but does not require authentication or special privileges. Successful exploitation allows writing files outside the intended extraction directory. The vulnerability has been patched in versions 3.1.1, 2.1.4, and 1.16.6. A workaround is available using the ignore option to filter out symlinks during extraction.
Affected products
- tar-fs tar-fs <1.16.6, <2.1.4, <3.1.1
Timeline
- 2025-09-24: disclosed
- 2025-09-24: patched: Patched in versions 3.1.1, 2.1.4, and 1.16.6