CVE-2025-59825 - CVE House
Back to Database
Status published Medium CVE-2025-59825

astral-tokio-tar has a path traversal in tar extraction

Vulnerability Description

astral-tokio-tar is a tar archive reading/writing library for async Rust. In versions 0.5.3 and earlier of astral-tokio-tar, tar archives may extract outside of their intended destination directory when using the Entry::unpack_in_raw API. Additionally, the Entry::allow_external_symlinks control (which defaults to true) could be bypassed via a pair of symlinks that individually point within the destination but combine to point outside of it. These behaviors could be used individually or combined to bypass the intended security control of limiting extraction to the given directory. This in turn would allow an attacker with a malicious tar archive to perform an arbitrary file write and potentially pivot into code execution. This issue has been patched in version 0.5.4. There is no workaround other than upgrading.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59825

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

tokio-tar
Vulnerable Versions:
< 0.5.4

Timeline

Official Publish: September 23rd, 2025
Last Modified: September 24th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)