Vulnerabilities (CVE)

Filtered by vendor Unjs Subscribe
Filtered by product Nanotar
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-69874 1 Unjs 1 Nanotar 2026-04-03 N/A 9.8 CRITICAL
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.