CVE-2024-12905 is a critical vulnerability affecting the tar-fs package (versions before 1.16.4, 2.1.2, and 3.0.8), allowing for arbitrary file writes or overwrites. This flaw, categorized as Improper Link Resolution and Path Traversal, occurs when extracting a specially crafted tar file. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to unauthorized system modifications. While there is an ExploitDB entry (EDB-52268) demonstrating arbitrary file write, there is no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Https://Registry.Npmjs.Org | Tar-Fs | >= 0.0.0, < 1.16.4, >= 2.0.0, < 2.1.2, >= 3.0.0, < 3.0.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
tar-fs vulnerabilities
Jun 2, 2026tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
Mar 27, 2025tar-fs: link following and path traversal via maliciously crafted tar file
Mar 27, 2025An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.
Mar 11, 2025