tar-fs@1.11.0 vulnerabilities

filesystem bindings for tar-stream

Direct Vulnerabilities

Known vulnerabilities in the tar-fs package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Arbitrary File Overwrite

tar-fs is a filesystem bindings for tar-stream.

Affected versions of this package are vulnerable to Arbitrary File Overwrite. An attacker can overwrite files on the system when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content.

How to fix Arbitrary File Overwrite?

Upgrade tar-fs to version 1.16.2 or higher.

<1.16.2