Junglewise Threat Intelligence

PsiTransfer path traversal in TAR archive download

Severity: low · CVSS 3.1 · Published 2025-12-30

Technologies: Psi-4ward Psitransfer. Vendors: npm.

Executive brief

PsiTransfer is a file-sharing application that allows users to upload and download files in bulk. A path traversal vulnerability in the archive download feature enables unauthenticated attackers to upload files with directory escape sequences (like "../../../") in filenames. When a victim extracts the resulting TAR archive, malicious files can be written anywhere on their filesystem, potentially leading to remote code execution.

Technical details

This is a Zip Slip path traversal vulnerability (CWE-22/CWE-23) in PsiTransfer's archive download functionality (lib/endpoints.js). The vulnerable code directly incorporates user-controlled file metadata.name into TAR archive entry names without sanitization. An unauthenticated attacker can exploit the TUS resumable upload protocol to upload a file with path traversal sequences in its filename metadata, then trigger archive download. When a victim extracts the .tar.gz file, the malicious entries write files outside the intended directory—for example, to ~/.ssh/authorized_keys or shell configuration files—enabling arbitrary code execution. The fix (released in v2.3.1) enforces safe filename validation.

Affected products

  • psi-4ward PsiTransfer <2.3.1

Timeline

  • 2025-12-29: disclosed
  • 2025-12-17: patched: Fix released in v2.3.1

References

Related threats