{"id":"RUSTSEC-2026-0328","summary":"`decompress`: tar-family extractors write archive entries without a path-traversal check (tar-slip)","details":"The tar-family extractors in `decompress` (`.tar`, `.tar.gz`, `.tar.xz`,\n`.tar.bz2`, `.tar.zst`) build each output path from the **raw archive entry path**\nand write to it with no traversal check, so a malicious archive can write files\n**outside** the destination directory, a \"tar-slip\" / zip-slip path traversal\n(CWE-22 / CWE-23).\n\nIn `src/decompressors/tar_common.rs` (`tar_extract`):\n\n```rust\nlet filepath = entry.path()?;                                    // raw entry path\nlet filepath = filepath.components().skip(opts.strip).collect::\u003cPathBuf\u003e();\n                                     // strips leading components only — keeps `..`\nlet outpath = to.join(filepath);\n// ...\nlet mut outfile = fs::File::create(&outpath)?;                   // writes anywhere\n```\n\n`.components().skip(opts.strip)` removes a fixed number of *leading* path\ncomponents but leaves interior `..` components intact so an entry named \ne.g. `../../../../home/\u003cuser\u003e/.bashrc`, or an absolute path, resolves **outside** \n`to`. This affects all platforms.","modified":"2026-10-03T07:30:03.083352599Z","published":"2026-09-19T12:00:00Z","database_specific":{"license":"CC0-1.0"},"references":[{"type":"PACKAGE","url":"https://crates.io/crates/decompress"},{"type":"ADVISORY","url":"https://rustsec.org/advisories/RUSTSEC-2026-0328.html"},{"type":"REPORT","url":"https://github.com/rusty-ferris-club/decompress/issues/21"}],"affected":[{"package":{"name":"decompress","ecosystem":"crates.io","purl":"pkg:cargo/decompress"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0.0.0-0"}]}],"ecosystem_specific":{"affects":{"os":[],"functions":["decompress::decompress"],"arch":[]},"affected_functions":null},"database_specific":{"cvss":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","source":"https://github.com/rustsec/advisory-db/blob/osv/crates/RUSTSEC-2026-0328.json","informational":null,"categories":["code-execution"]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H"}]}