OpenSearch-Dashboards
OpenSearch-Dashboards copied to clipboard
CVE-2025-48387 (High) detected in tar-fs-3.0.8.tgz, tar-fs-2.1.2.tgz
CVE-2025-48387 - High Severity Vulnerability
Vulnerable Libraries - tar-fs-3.0.8.tgz, tar-fs-2.1.2.tgz
filesystem bindings for tar-stream Library home page: https://registry.npmjs.org/tar-fs/-/tar-fs-3.0.8.tgz Path to dependency file: /package.json Path to vulnerable library: /package.json
Dependency Hierarchy: filesystem bindings for tar-stream Library home page: https://registry.npmjs.org/tar-fs/-/tar-fs-2.1.2.tgz Path to dependency file: /package.json Path to vulnerable library: /package.json
Dependency Hierarchy:tar-fs-3.0.8.tgz
tar-fs-2.1.2.tgz
Found in HEAD commit: 4fd064970b66ce555f48c22dfab6ed965d0e260a
Found in base branch: main
Vulnerability Details
tar-fs provides filesystem bindings for tar-stream. Versions prior to 3.0.9, 2.1.3, and 1.16.5 have an issue where an extract can write outside the specified dir with a specific tarball. This has been patched in versions 3.0.9, 2.1.3, and 1.16.5. As a workaround, use the ignore option to ignore non files/directories.
Publish Date: 2025-06-02
URL: CVE-2025-48387
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: https://github.com/advisories/GHSA-8cj5-5rvv-wf4v
Release Date: 2025-06-02
Fix Resolution: tar-fs - 2.1.3