MEDIUM
GHSA-92fh-27vv-894w
nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()
Details
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/nanotar
Introduced in:
0No fixed version published yet for nanotar (npm). Pin to a known-safe version or switch to an alternative.