Junglewise Threat Intelligence

CVE-2026-45390: OCaml-tar path traversal in archive extraction

CVE-2026-45390 · Severity: info · CVSS 8.2 · Published 2026-06-15

Vendors: OCaml.

Executive brief

OCaml-tar is a library used by developers to handle tar archive files within OCaml applications. A security flaw allows a specially crafted archive to write files to locations on the system outside of the intended folder. If an application uses this library to process untrusted files, an attacker could potentially overwrite sensitive system files or configuration data, leading to a compromise of the host system.

Technical details

A path traversal vulnerability exists in OCaml-tar (opam package 'tar') prior to version 3.5.0. The `Tar_unix.extract` function utilizes `Filename.concat` to join the destination directory with the filename provided in the archive header. Because `Filename.concat` does not sanitize or validate the resulting path, an archive containing '..' segments can resolve to locations outside the target directory. An attacker can exploit this by providing a malicious tarball to any application using the library for extraction, resulting in arbitrary file writes. The issue is fixed in version 3.5.0 by implementing path sanitization.

Affected products

  • OCaml tar < 3.5.0

Timeline

  • 2026-05-07: disclosed: Reported via GitHub
  • 2026-05-22: patched: Fixed version 3.5.0 released
  • 2026-06-15: advisory: CVE-2026-45390 published