Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2024-12905Path Traversal in Node-tar-fs

Severity
7.5HIGHNVD
EPSS
1.3%
top 20.10%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedMar 27
Latest updateSep 26

Description

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages3 packages

debiandebian/node-tar-fs< node-tar-fs 2.1.3-0+deb12u1 (bookworm)
npmtar-fs_project/tar-fs2.0.02.1.2+2

🔴Vulnerability Details

3
GHSA
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File2025-03-27
OSV
tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File2025-03-27
OSV
CVE-2024-12905: An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal")2025-03-27

💥Exploits & PoCs

1
Exploit-DB
tar-fs 3.0.0 - Arbitrary File Write/Overwrite2025-04-22

📋Vendor Advisories

3
Red Hat
tar-fs: link following and path traversal via maliciously crafted tar file2025-03-27
Microsoft
An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a malici2025-03-11
Debian
CVE-2024-12905: node-tar-fs - An Improper Link Resolution Before File Access ("Link Following") and Improper L...2024

📄Research Papers

2
arXiv
PoCGen: Generating Proof-of-Concept Exploits for Vulnerabilities in Npm Packages2025-09-26
arXiv
Security Vulnerabilities in Software Supply Chain for Autonomous Vehicles2025-09-21
CVE-2024-12905 — Path Traversal in Debian Node-tar-fs | cvebase