HIGH
GHSA-vj76-c3g6-qr5v
tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
Quick fix
GHSA-vj76-c3g6-qr5v — tar-fs: upgrade to the fixed version with the command below.
npm install tar-fs@3.1.1Details
### Impact v3.1.0, v2.1.3, v1.16.5 and below
### Patches Has been patched in 3.1.1, 2.1.4, and 1.16.6
### Workarounds You can use the ignore option to ignore non files/directories.
```js ignore (_, header) { // pass files & directories, ignore e.g. symlinks return header.type !== 'file' && header.type !== 'directory' } ```
### Credit Reported by: Mapta / BugBunny_ai
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/mafintosh/tar-fs/security/advisories/GHSA-vj76-c3g6-qr5v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-59343[ADVISORY]
- https://github.com/mafintosh/tar-fs/commit/0bd54cdf06da2b7b5b95cd4b062c9f4e0a8c4e09[WEB]
- https://github.com/mafintosh/tar-fs[PACKAGE]
- https://lists.debian.org/debian-lts-announce/2025/09/msg00028.html[WEB]