The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz,
.tar.bz2, .tar.zst) build each output path from the raw archive entry path
and write to it with no traversal check, so a malicious archive can write files
outside the destination directory, a "tar-slip" / zip-slip path traversal
(CWE-22 / CWE-23).
In src/decompressors/tar_common.rs (tar_extract):
let filepath = entry.path()?; // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
// strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?; // writes anywhere
.components().skip(opts.strip) removes a fixed number of leading path
components but leaves interior .. components intact so an entry named
e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside
to. This affects all platforms.
{
"license": "CC0-1.0"
}