Filtered by vendor Unjs Subscriptions
Filtered by product Nanotar Subscriptions
Total 1 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-69874 1 Unjs 1 Nanotar 2026-02-12 N/A
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.