OpenSearch-Dashboards icon indicating copy to clipboard operation
OpenSearch-Dashboards copied to clipboard

CVE-2025-48387 (High) detected in tar-fs-3.0.8.tgz, tar-fs-2.1.2.tgz

Open mend-for-github-com[bot] opened this issue 6 months ago • 0 comments

CVE-2025-48387 - High Severity Vulnerability

Vulnerable Libraries - tar-fs-3.0.8.tgz, tar-fs-2.1.2.tgz

tar-fs-3.0.8.tgz

filesystem bindings for tar-stream

Library home page: https://registry.npmjs.org/tar-fs/-/tar-fs-3.0.8.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • puppeteer-24.4.0.tgz (Root Library)
    • browsers-2.8.0.tgz
      • :x: tar-fs-3.0.8.tgz (Vulnerable Library)
tar-fs-2.1.2.tgz

filesystem bindings for tar-stream

Library home page: https://registry.npmjs.org/tar-fs/-/tar-fs-2.1.2.tgz

Path to dependency file: /package.json

Path to vulnerable library: /package.json

Dependency Hierarchy:

  • @osd/test-1.0.0.tgz (Root Library)
    • :x: tar-fs-2.1.2.tgz (Vulnerable Library)

Found in HEAD commit: 4fd064970b66ce555f48c22dfab6ed965d0e260a

Found in base branch: main

Vulnerability Details

tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.

Publish Date: 2025-06-02

URL: CVE-2025-48387

CVSS 3 Score Details (7.5)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Network
    • Attack Complexity: Low
    • Privileges Required: None
    • User Interaction: None
    • Scope: Unchanged
  • Impact Metrics:
    • Confidentiality Impact: None
    • Integrity Impact: High
    • Availability Impact: None
For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: https://github.com/advisories/GHSA-8cj5-5rvv-wf4v

Release Date: 2025-06-02

Fix Resolution: tar-fs - 2.1.3