PT-2025-39215 · Unknown+1 · Astral-Tokio-Tar+1

Published

2025-09-23

·

Updated

2025-11-26

·

CVE-2025-59825

CVSS v4.0

6.1

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U
Name of the Vulnerable Software and Affected Versions astral-tokio-tar versions 0.5.3 and earlier
Description astral-tokio-tar is a tar archive reading/writing library for async Rust. Tar archives may extract files outside of their intended destination directory when using the Entry::unpack in raw API. The Entry::allow external symlinks control could be bypassed using symlinks that, when combined, point outside the destination directory. These behaviors could allow an attacker with a malicious tar archive to perform arbitrary file writes and potentially achieve code execution.
Recommendations Upgrade to version 0.5.4 or later.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-59825
GHSA-3WGQ-WRWC-VQMV

Affected Products

Debian
Astral-Tokio-Tar