VDB
KO
HIGH 7.5

GHSA-gfjr-3jmm-4g9v

Symlink Arbitrary File Overwrite in tar

Details

Versions of `tar` prior to 2.0.0 are affected by an arbitrary file write vulnerability. The vulnerability occurs because `tar` does not verify that extracted symbolic links to not resolve to targets outside of the extraction root directory.

## Recommendation

Update to version 2.0.0 or later

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / tar
Introduced in: 0 Fixed in: 2.0.0
Fix npm install tar@2.0.0

References