CVE-2025-59343

EUVD-2025-31022
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 7%
Debian logo
Debian Releases
Debian Product
Codename
node-tar-fs
bookworm
2.1.3-0+deb12u2
fixed
bookworm (security)
2.1.3-0+deb12u2
fixed
bullseye
vulnerable
bullseye (security)
2.1.3-0+deb11u2
fixed
forky
3.0.9+~cs2.0.4-2
fixed
sid
3.0.9+~cs2.0.4-2
fixed
trixie
3.0.9+~cs2.0.4-1+deb13u1
fixed
trixie (security)
3.0.9+~cs2.0.4-1+deb13u1
fixed