Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-12905

34
FAUCET Score

CVE-2024-12905 is a critical vulnerability affecting the tar-fs package (versions before 1.16.4, 2.1.2, and 3.0.8), allowing for arbitrary file writes or overwrites. This flaw, categorized as Improper Link Resolution and Path Traversal, occurs when extracting a specially crafted tar file. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to unauthorized system modifications. While there is an ExploitDB entry (EDB-52268) demonstrating arbitrary file write, there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
Https://Registry.Npmjs.OrgTar-Fs
>= 0.0.0, < 1.16.4, >= 2.0.0, < 2.1.2, >= 3.0.0, < 3.0.8CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.21%
Probability of exploitation in next 30 days
EPSS Percentile
80.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-52268 · Apr 22, 2025
This CVE's current EPSS score of 0.0221 is in the 65th percentile among its peer group of 51,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (28)

microsoftpatch availablevia msrc
Product: cbl2 reaper 3.1.1-18 on CBL Mariner 2.0Fixed in: 3.1.1-18
microsoftpatch availablevia msrc
Product: 19820-17086Fixed in: 3.1.1-18
npmpatch availablevia ghsa
Product: tar-fsFixed in: 3.0.7
npmpatch availablevia ghsa
Product: tar-fsFixed in: 1.16.4
npmpatch availablevia ghsa
Product: tar-fsFixed in: 2.1.2
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/pluginregistry-rhel9:3.20-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/dashboard-rhel9:3.21-12
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/devspaces-operator-bundle:3.21-25
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/devspaces-rhel9-operator:3.21-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/imagepuller-rhel9:3.21-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/machineexec-rhel9:3.21-4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/pluginregistry-rhel9:3.21-7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/server-rhel9:3.21-11
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces-tech-preview/idea-rhel9:3.21-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces-tech-preview/jetbrains-ide-rhel9:3.21-3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/traefik-rhel9:3.21-1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/udi-base-rhel9:3.21-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/udi-rhel9:3.21-6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.5Fixed in: rhdh/rhdh-hub-rhel9:sha256:e76a91d43f5fb482b19a42bf2cfc30e183b1331f6db600855600b5a917c889b3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Developer Hub 1.6Fixed in: rhdh/rhdh-hub-rhel9:sha256:b6bf7ded5e146f60141840bb2e42e72125c61af0f3d3c3fbf48b35bc670675fe
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/code-rhel9:3.21-5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Dev Spaces 3 ContainersFixed in: devspaces/configbump-rhel9:3.21-5
View patch
ubuntupatch availablevia ubuntu_usn
Product: node-tar-fs (jammy)Fixed in: 2.1.1-6ubuntu0.22.04.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: node-tar-fs (noble)Fixed in: 2.1.1-6ubuntu0.24.04.1~esm1
ubuntupatch availablevia ubuntu_usn
Product: node-tar-fs (questing)Fixed in: 3.0.9+~cs2.0.4-1+deb13u1build0.25.10.1
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 9Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 7Fixed in: ceph
redhatno patchvia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: ceph

Vendor Advisories (4)

ubuntuUSN-8367-1

tar-fs vulnerabilities

Jun 2, 2026
npmGHSA-pq67-2wwv-3xjxhigh

tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File

Mar 27, 2025
redhatCVE-2024-12905Important

tar-fs: link following and path traversal via maliciously crafted tar file

Mar 27, 2025
microsoft2025-Mar/CVE-2024-12905Important

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

Mar 11, 2025

References

github.com / mafintosh/tar-fs/commit/a1dd7e7c7f4b4a8bd2ab60f513baca573b44e2ed
seal.security / blog/a-link-to-the-past-uncovering-a-new-vulnerability-in-tar-fs
lists.debian.org / debian-lts-announce/2025/06/msg00012.html