Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-92fh-27vv-894w | nanotar is vulnerable to path traversal in parseTar() and parseTarGzip() |
Fri, 03 Apr 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:unjs:nanotar:*:*:*:*:*:node.js:*:* |
Thu, 12 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| Metrics |
cvssV3_1
|
Thu, 12 Feb 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Unjs
Unjs nanotar |
|
| Vendors & Products |
Unjs
Unjs nanotar |
Wed, 11 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-12T14:49:30.529Z
Reserved: 2026-01-09T00:00:00.000Z
Link: CVE-2025-69874
Updated: 2026-02-12T14:48:47.303Z
Status : Analyzed
Published: 2026-02-11T18:16:05.430
Modified: 2026-04-03T11:32:27.587
Link: CVE-2025-69874
No data.
OpenCVE Enrichment
Updated: 2026-02-12T11:19:26Z
Github GHSA