VendorsUnJSnanotarany version
Vulnerabilities

UnJS nanotar any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-69874
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
Published 2026-02-11 · Analyzed
9.8EPSS 0.009