Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4214-1 | node-tar-fs security update |
EUVD |
EUVD-2025-16687 | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories. |
Github GHSA |
GHSA-8cj5-5rvv-wf4v | tar-fs can extract outside the specified dir with a specific tarball |
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 14 Aug 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 01 Jul 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat rhdh |
|
| CPEs | cpe:/a:redhat:rhdh:1.6::el9 | |
| Vendors & Products |
Redhat
Redhat rhdh |
Tue, 03 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Tue, 03 Jun 2025 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Jun 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories. | |
| Title | tar-fs has issue where extract can write outside the specified dir with a specific tarball | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-03T20:04:45.253Z
Reserved: 2025-05-19T15:46:00.397Z
Link: CVE-2025-48387
Updated: 2025-11-03T20:04:45.253Z
Status : Deferred
Published: 2025-06-02T20:15:22.930
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-48387
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA