RUSTSEC-2026-0328High· 7.1▾ Twilight`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz,
.tar.bz2, .tar.zst) build each output path from the raw archive entry path
and write to it with no traversal check, so a malicious archive can write files
outside the destination directory, a "tar-slip" / zip-slip path traversal
(CWE-22 / CWE-23).
In src/decompressors/tar_common.rs (tar_extract):
let filepath = entry.path()?; // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
// strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?; // writes anywhere
.components().skip(opts.strip) removes a fixed number of leading path
components but leaves interior .. components intact so an entry named
e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside
to. This affects all platforms.
decompress >= 0.0.0-0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-101894Critical· 9.1The decompress package for Node.js extracts archives
CVE-2026-39246High· 7.5decompress before 4.2.2 allows arbitrary symlink creation during archive extraction
CVE-2026-39245Medium· 6.2decompress before 4.2.2 contains an improper path containment check that enables directory traversal and arbitrary file write
CVE-2026-39243Medium· 5.5decompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption