CVE-2025-69874 is a critical path traversal vulnerability affecting unjs nanotar through version 0.2.0. This flaw allows remote attackers to write arbitrary files outside the intended extraction directory by processing a specially crafted tar archive. Rated with a CVSS score of 9.8 (Critical), the vulnerability requires no authentication or user interaction and can be exploited over the network with low complexity, leading to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, nor is it listed in CISA's KEV catalog or any public exploit databases like Metasploit or ExploitDB. Community discussion and media coverage are also absent, indicating low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.2.0CPE matchmatch criteria | cpe:2.3:a:unjs:nanotar:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.