CVE-2020-36566: Tar-Utils Project Tar-Utils

Critical severity, CVSS 9.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory.

Affected products

  • Tar-Utils Project Tar-Utils: before 0.0.0-20201201191210-20a61371de5b (fixed in 0.0.0-20201201191210-20a61371de5b)

Published 2022-12-27. Last modified 2026-06-17.