Vulnerability RUSTSEC-2026-0328

High Risk
HIGH RISK
CVSS Score: 7.1
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
13 days ago
September 19, 2026 at 12:00 PM UTC
`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)
0.1.0 - 0.6.0
0.1.0 - 0.6.0

Summary

`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)

Details

The tar-family extractors in decompress (.tar, .tar.gz, .tar.xz, .tar.bz2, .tar.zst) build each output path from the raw archive entry path and write to it with no traversal check, so a malicious archive can write files outside the destination directory, a "tar-slip" / zip-slip path traversal (CWE-22 / CWE-23).

In src/decompressors/tar_common.rs (tar_extract):

let filepath = entry.path()?;                                    // raw entry path
let filepath = filepath.components().skip(opts.strip).collect::<PathBuf>();
                                     // strips leading components only — keeps `..`
let outpath = to.join(filepath);
// ...
let mut outfile = fs::File::create(&outpath)?;                   // writes anywhere

.components().skip(opts.strip) removes a fixed number of leading path components but leaves interior .. components intact so an entry named e.g. ../../../../home/<user>/.bashrc, or an absolute path, resolves outside to. This affects all platforms.

Impacted packages

Timeline

Published
13 days ago
September 19, 2026 at 12:00 PM UTC
Last Modified
1 hour ago
October 03, 2026 at 07:30 AM UTC