Tar Path Traversal Escapes Extraction Directory
Tar archives can contain entries with ../ path segments, so a naive extractor writes files outside the intended destination directory — a path-traversal flaw that lets a malicious archive overwrite configuration files, startup scripts, or libraries on the host. The attack requires no exploit of the extracting application itself; the archive format simply permits the traversal. This demo uses a benign tar with traversal-style entries to show why extraction-time defenses matter. MetaDefender Archive Engine validates every entry path against the extraction root, rejects or neutralizes entries containing parent-directory references, and blocks the archive before any file escapes its sandboxed destination.
Attack Technique
Tar path traversal
MITRE ATT&CK
T1027.003 ↗Platforms
File Types
MetaDefender Capabilities
Incident Coverage
This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗