{"id":"GHSA-xx64-wwv2-hcqq","aliases":["RUSTSEC-2026-0113"],"url":"https://o3.security/vulnerability/GHSA-xx64-wwv2-hcqq","summary":"astral-tokio-tar: `unpack_in` can chmod arbitrary directories by following symlinks","details":"### Impact\n\nIn versions 0.6.0 and earlier of astral-tokio-tar, the `unpack_in` API could inadvertently modify the permissions of external (i.e. non-archive) directories outside of the archive. An attacker could use this to contrite a tar archive that maliciously changes directory permissions outside of its intended hierarchy. This flaw only affects directories; individual file permissions cannot be modified via it.\n\nSee GHSA-j4xf-2g29-59ph for the equivalent flaw in the `tar` crate.\n\n### Patches\n\nVersions 0.6.1 and newer of astral-tokio-tar use `fs::symlink_metdata` rather than `fs::metadata`, avoiding the traversal. \n\n### Workarounds\n\nUsers are advised to upgrade to version 0.6.1 or newer to address this advisory.\n\nUsers should experience no breaking changes as a result of the patch above.\n\n### Resources\n\n- GHSA-j4xf-2g29-59ph for the original `tar` vulnerability\n\n### Attribution\n\n- Reporter: Adam Harvey (@lawngnome)","published":"2026-05-06T17:26:38Z","modified":"2026-09-10T03:51:07.301797464Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"astral-tokio-tar","fixedVersion":"0.6.1"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/astral-sh/tokio-tar/security/advisories/GHSA-xx64-wwv2-hcqq"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-xx64-wwv2-hcqq"},{"type":"PACKAGE","url":"https://github.com/astral-sh/tokio-tar"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2026-0113.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:51:07.301797464Z"}}