HIGH
GHSA-8cj5-5rvv-wf4v
tar-fs can extract outside the specified dir with a specific tarball
Quick fix
GHSA-8cj5-5rvv-wf4v — tar-fs: upgrade to the fixed version with the command below.
npm install tar-fs@1.16.5Details
### Impact v3.0.8, v2.1.2, v1.16.4 and below
### Patches Has been patched in 3.0.9, 2.1.3, and 1.16.5
### Workarounds You can use the ignore option to ignore non files/directories.
```js ignore (_, header) { // pass files & directories, ignore e.g. symlinks return header.type !== 'file' && header.type !== 'directory' } ```
### Credit Thank you Caleb Brown from Google Open Source Security Team for reporting this in detail.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/google/security-research/security/advisories/GHSA-xrg4-qp5w-2c3w[WEB]
- https://github.com/mafintosh/tar-fs/security/advisories/GHSA-8cj5-5rvv-wf4v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-48387[ADVISORY]
- https://github.com/mafintosh/tar-fs/commit/647447b572bc135c41035e82ca7b894f02b17f0f[WEB]
- https://github.com/mafintosh/tar-fs[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/06/msg00012.html[WEB]