← Back to CVE intelligence
CVE intelligence

CVE-2024-12905

Vulnerability intelligence

Published Mar 27, 2025Sources checked Sep 30, 2026
7.5HIGHCVSS out of 10
What this means

Review the available evidence

CVE-2024-12905 and is rated High severity with a CVSS score of 7.5. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.

Public exploit: Cataloged public exploit.

What to do next

Remediation and response

CISA KEVNot listedBased on the latest collected catalog
EPSS2.3%Estimated 30-day exploitation probability
Ransomware useNot markedCISA KEV ransomware field
Threat actors0Source-linked actor relationships
Overview

What is CVE-2024-12905?

An Improper Link Resolution Before File Access ("Link Following") and Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal"). This vulnerability occurs when extracting a maliciously crafted tar file, which can result in unauthorized file writes or overwrites outside the intended extraction directory. The issue is associated with index.js in the tar-fs package. This issue affects tar-fs: from 0.0.0 before 1.16.4, from 2.0.0 before 2.1.2, from 3.0.0 before 3.0.8.