CVE-2025-59343
NPM Tar-fs < 3.1.1 - Path Traversal
Title source: ruleDescription
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.1.1, 2.1.3, and 1.16.5 are vulnerable to symlink validation bypass if the destination directory is predictable with a specific tarball. This issue has been patched in version 3.1.1, 2.1.4, and 1.16.6. A workaround involves using the ignore option on non files/directories.
References (3)
Scores
EPSS
0.0003
EPSS Percentile
8.2%
Classification
CWE
CWE-22
CWE-61
Status
draft
Affected Products (1)
npm/tar-fs
< 3.1.1npm
Timeline
Published
Sep 24, 2025
Tracked Since
Feb 18, 2026