CVE-2024-12905 Information
Mar 28, 2025
cve
Description
An Improper Link Resolution Before File Access (\Link Following) and Improper Limitation of a Pathname to a Restricted Directory (\Path Traversal). This vulnerability occurs when extracting a maliciously crafted tar file which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package.
This issue affects tar-fs: from 0.0.0 before 1.16.4 from 2.0.0 before 2.1.2 from 3.0.0 before 3.0.8.
Reference
https://github.com/mafintosh/tar-fs/commit/a1dd7e7c7f4b4a8bd2ab60f513baca573b44e2ed
Share on: