Intel

AIKIDO-2026-10683

astral-tokio-tar is vulnerable to Improper Input Validation

Improper Input ValidationGHSA-fp55-jw48-c537 Published Apr 30, 2026

50

Medium Risk

This Affects:

RUSTastral-tokio-tar
0.0.1 - 0.6.0
Fixed in 0.6.1
Are you affected? Scan for Free

TL;DR

Affected versions of this package contain a PAX header interpretation bug that allows manipulated entries to be made selectively visible or invisible during extraction with astral-tokio-tar versus other tar implementations. An attacker could use this differential to smuggle unexpected files onto a victim's filesystem.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astral-tokio-tar is vulnerable to Improper Input Validation in versions 0.0.1 - 0.6.0.

How to fix this

Upgrade the astral-tokio-tar library to the patch version.