Skip to main content
← Back to Demos
Archive Abuse intermediate · 15 min

Tar Path Traversal Escapes Extraction Directory

Tar archives can contain entries with ../ path segments, so a naive extractor writes files outside the intended destination directory — a path-traversal flaw that lets a malicious archive overwrite configuration files, startup scripts, or libraries on the host. The attack requires no exploit of the extracting application itself; the archive format simply permits the traversal. This demo uses a benign tar with traversal-style entries to show why extraction-time defenses matter. MetaDefender Archive Engine validates every entry path against the extraction root, rejects or neutralizes entries containing parent-directory references, and blocks the archive before any file escapes its sandboxed destination.

Attack Technique

Tar path traversal

MITRE ATT&CK

T1027.003 ↗

Platforms

linuxwindows

File Types

.tar

MetaDefender Capabilities

Archive Engine

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---