RustSec logo

History ⋅ Edit ⋅ JSON (OSV)

RUSTSEC-2026-0328

decompress: tar-family extractors write archive entries without a path-traversal check (tar-slip)

Reported
Issued
Package
decompress (crates.io)
Type
Vulnerability
Categories
Keywords
#zip-slip #tar-slip #path-traversal #directory-traversal #arbitrary-file-write
References
CVSS Score
7.1 HIGH
CVSS Details
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality Impact
None
Integrity Impact
High
Availability Impact
High
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Patched
no patched versions
Affected Functions
Version
decompress::decompress
  • <=0.6.0

Description

The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz, .tar.bz2, .tar.zst) build each output path from the raw archive entry path and write to it with no traversal check, so a malicious archive can write files outside the destination directory, a "tar-slip" / zip-slip path traversal (CWE-22 / CWE-23).

In src/decompressors/tar_common.rs (tar_extract):

let filepath = entry.path()?;                                    // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
                                     // strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?;                   // writes anywhere

.components().skip(opts.strip) removes a fixed number of leading path components but leaves interior .. components intact so an entry named e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside to. This affects all platforms.

Advisory available under CC0-1.0 license.