Minitar is a Ruby archive-handling library for TAR file creation and extraction, presenting a narrow but focused exposure surface through its archive-tar-minitar product. The durable vulnerability signal centers on path-traversal conditions in pathname handling during TAR operations, a characteristic weakness in archive processors that unpack untrusted or malformed archives. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minitar over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-10173HIGH Directory traversal vulnerability in the minitar before 0.6 and archive-tar-minitar 0.5.2 gems for Ruby allows remote attackers to write to arbitrary files via a .. (dot dot) in a | Feb 1, 2017 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minitar.
Media articles that mention a CVE ID that affects a product developed by Minitar — matched by CVE ID, not by vendor name.