CVE-2025-69874: Path Traversal
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-69874?
The severity of CVE-2025-69874 is considered to be high due to its potential for remote exploitation and arbitrary file writing.
How do I fix CVE-2025-69874?
To fix CVE-2025-69874, upgrade to version 0.2.1 or later of the nanotar package.
What does CVE-2025-69874 affect?
CVE-2025-69874 affects the nanotar package version 0.2.0 and earlier, which allows for path traversal vulnerabilities.
What is the nature of the vulnerability in CVE-2025-69874?
CVE-2025-69874 is a path traversal vulnerability that allows exploitation via crafted tar archives.
Can CVE-2025-69874 be exploited remotely?
Yes, CVE-2025-69874 can be exploited remotely, enabling attackers to write files outside the intended directory.