Signal is active with 1 mentions in latest observed window
Immediate actions
Track advisory updates for patch or workaround availability
Recommended action window: Monitor and triage in normal cycle
NVD description
nanotar through 0.2.0 has a path traversal vulnerability in parseTar() and parseTarGzip() that allows remote attackers to write arbitrary files outside the intended extraction directory via a crafted tar archive containing path traversal sequence.
CVE-2025-69874: nanotar Zip Slip: When "Lightweight" Means "Security Optional"
A high-severity Path Traversal (Zip Slip) vulnerability exists in `nanotar` versions <= 0.2.0. The library, designed as a lightweight tar parser for the UnJS ecosystem, fai...
https://cvereports.com/reports/CVE-2025-69874
Post summary
CVE-2025-69874 is a high‑severity Path Traversal (Zip Slip) vulnerability affecting nanotar versions up to 0.2.0, with no PoC, exploit, or patch information disclosed in the text.