CVE-2025-48387

EUVD-2025-16687
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 42.18%
Debian logo
Debian Releases
Debian Product
Codename
node-tar-fs
bookworm
2.1.3-0+deb12u2
fixed
bookworm (security)
2.1.3-0+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
2.1.3-0+deb11u2
fixed
forky
3.1.2+~cs2.0.4-1
fixed
sid
3.1.2+~cs2.0.4-1
fixed
trixie
3.0.9+~cs2.0.4-1+deb13u1
fixed
trixie (security)
3.0.9+~cs2.0.4-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
node-tar-fs
focal
dne
jammy
Fixed 2.1.1-6ubuntu0.22.04.1~esm1
released
noble
Fixed 2.1.1-6ubuntu0.24.04.1~esm1
released
oracular
ignored
plucky
ignored
questing
not-affected
resolute
not-affected
Azure Linux logo
Azure Linux Releases
Azure Package
Release
reaper
CBL-Mariner 2.0
0:3.1.1-19.cm2
fixed