CVE-2025-59343: tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball
(updated )
v3.1.0, v2.1.3, v1.16.5 and below
References
Code Behaviors & Features
Detect and mitigate CVE-2025-59343 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →