{"id":"RUSTSEC-2026-0328","title":"`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)","summary":"`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)","severity":"high","cvss":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","vendor":"decompress","product":"decompress","ecosystem":"rust","affected":["decompress >= 0.0.0-0"],"published":"2026-09-19","updated":"2026-10-03","sourceUpdated":"2026-10-03T07:30:03.083352599Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/RUSTSEC-2026-0328","references":[{"url":"https://crates.io/crates/decompress"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0328.html"},{"url":"https://github.com/rusty-ferris-club/decompress/issues/21"}],"tags":["osv","rust"],"ingestedAt":"2026-10-04T07:27:31.044Z","slug":"RUSTSEC-2026-0328","body":"## Overview\n\nThe tar-family extractors in `decompress` (`.tar`, `.tar.gz`, `.tar.xz`,\n`.tar.bz2`, `.tar.zst`) build each output path from the **raw archive entry path**\nand write to it with no traversal check, so a malicious archive can write files\n**outside** the destination directory, a \"tar-slip\" / zip-slip path traversal\n(CWE-22 / CWE-23).\n\nIn `src/decompressors/tar_common.rs` (`tar_extract`):\n\n```rust\nlet filepath = entry.path()?;                                    // raw entry path\nlet filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();\n                                     // strips leading components only — keeps `..`\nlet outpath = to.join(filepath);\n// ...\nlet mut outfile = fs::File::create(&outpath)?;                   // writes anywhere\n```\n\n`.components().skip(opts.strip)` removes a fixed number of *leading* path\ncomponents but leaves interior `..` components intact so an entry named \ne.g. `../../../../home/<user>/.bashrc`, or an absolute path, resolves **outside** \n`to`. This affects all platforms.\n\n## Affected packages\n\n- `decompress >= 0.0.0-0`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}