Intel

AIKIDO-2026-10896

astral-tokio-tar is vulnerable to Improper Input Validation

Improper Input ValidationGHSA-3cv2-h65g-fgmm Published 6 days ago

50

Medium Risk

This Affects:

RUSTastral-tokio-tar
0.0.1 - 0.6.1
Fixed in 0.6.2
Are you affected? Scan for Free

TL;DR

astral-tokio-tar versions prior to 0.6.2 contain a PAX header interpretation flaw that causes tar archives to be processed differently than by other tar implementations. A crafted archive can manipulate header handling to selectively hide or expose files during extraction, potentially allowing attackers to smuggle unexpected files onto a victim’s filesystem.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

astral-tokio-tar is vulnerable to Improper Input Validation in versions 0.0.1 - 0.6.1.

How to fix this

Upgrade the astral-tokio-tar library to the patch version.