CVE-2025-69874
EUVD-2025-20739711.02.2026, 18:16
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| unjs | nanotar | 𝑥 ≤ 0.2.0 |
𝑥
= Vulnerable software versions