PT-2026-7626 · Nanotar · Nanotar

Published

2026-02-11

·

Updated

2026-02-12

·

CVE-2025-69874

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nanotar versions through 0.2.0
Description The nanotar software contains a path traversal flaw within the parseTar() and parseTarGzip() functions. This allows attackers to potentially write files to locations outside the intended extraction directory by supplying a specially crafted tar archive that includes path traversal sequences.
Recommendations Update to a version of nanotar greater than 0.2.0.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-69874
GHSA-92FH-27VV-894W

Affected Products

Nanotar