CVE Database
/

CVE-2025-59343

Back to search

CVE-2025-59343

Published: Sep 24, 2025

Modified: Nov 3, 2025

PUBLISHED

Description

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.

VendorProductVersions

mafintosh

tar-fs

affected
>= 3.0.0, < 3.1.1
affected
>= 2.0.0, < 2.1.3
affected
< 1.16.5

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now