RUSTSEC-2026-0328

Source
https://rustsec.org/advisories/RUSTSEC-2026-0328
Import Source
https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0328.json
JSON Data
https://api.osv.dev/v1/vulns/RUSTSEC-2026-0328
Published
2026-09-19T12:00:00Z
Modified
2026-10-03T07:30:03Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H CVSS Calculator
Summary
`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)
Details

The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz, .tar.bz2, .tar.zst) build each output path from the raw archive entry path and write to it with no traversal check, so a malicious archive can write files outside the destination directory, a "tar-slip" / zip-slip path traversal (CWE-22 / CWE-23).

In src/decompressors/tar_common.rs (tar_extract):

let filepath = entry.path()?;                                    // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
                                     // strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?;                   // writes anywhere

.components().skip(opts.strip) removes a fixed number of leading path components but leaves interior .. components intact so an entry named e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside to. This affects all platforms.

Database specific
{
    "license":  "CC0-1.0"
}
References

Affected packages

crates.io / decompress

Package

Name
decompress
View open source insights on deps.dev
Purl
pkg:cargo/decompress

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0-0

Ecosystem specific

{
    "affected_functions":  null,
    "affects":  {
        "arch":  [],
        "functions":  [
            "decompress::decompress"
        ],
        "os":  []
    }
}

Database specific

categories
[
    "code-execution"
]
cvss
"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"
informational
null
source
"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0328.json"