{"id":"GHSA-92fh-27vv-894w","summary":"nanotar is vulnerable to path traversal in parseTar() and parseTarGzip()","details":"nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.","aliases":["CVE-2025-69874"],"modified":"2026-02-11T19:11:16.577195Z","published":"2026-02-11T18:31:30Z","database_specific":{"nvd_published_at":"2026-02-11T18:16:05Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-02-11T18:56:22Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69874"},{"type":"WEB","url":"https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69874-nanotar-Path-Traversal.md"},{"type":"PACKAGE","url":"https://github.com/unjs/nanotar"},{"type":"WEB","url":"https://www.npmjs.com/package/nanotar"}],"affected":[{"package":{"name":"nanotar","ecosystem":"npm","purl":"pkg:npm/nanotar"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-92fh-27vv-894w/GHSA-92fh-27vv-894w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N"}]}