VDB
Sign up
MEDIUM

GHSA-92fh-27vv-894w

nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()

Details

nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nanotar
Introduced in: 0

No fixed version published yet for nanotar (npm). Pin to a known-safe version or switch to an alternative.

References