From 499f010527d0d514ce5dc6abf6418525224a22c5 Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Wed, 7 Oct 2026 13:15:50 +0000 Subject: [PATCH] Fix directory traversal vulnerability in untar_archive Co-authored-by: Tcode-Motion <188012755+Tcode-Motion@users.noreply.github.com> --- stdlib/src/compress.rs | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/stdlib/src/compress.rs b/stdlib/src/compress.rs index d1daf83b..97582a98 100644 --- a/stdlib/src/compress.rs +++ b/stdlib/src/compress.rs @@ -258,7 +258,10 @@ pub fn untar_archive(archive_path: &str, dest_dir: &str) -> std::io::Result<()> // from escaping the destination directory. Therefore, we revert the manual // path validation that caused a regression with uncanonicalized relative paths. - a.unpack(dest_dir)?; + for entry in a.entries()? { + let mut entry = entry?; + entry.unpack_in(dest_dir)?; + } Ok(()) }