Vulnerability record · CVE-2020-28948 · published 19 November 2020
CVE-2020-28948: Archive_Tar case-sensitive phar block bypass enables PHP object injection
Php · Archive Tar
Archive_Tar through 1.4.10 blocks the phar: stream wrapper but not the uppercase PHAR: form, so a crafted archive path can trigger PHP unserialization of untrusted data. Because Archive_Tar is bundled with PHP and used by projects such as Drupal, any application extracting attacker-supplied archives is exposed to object injection.
Description
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high EPSS and a public exploit reference makes this a realistic target despite the local vector and required user interaction.
What it is
Archive_Tar through 1.4.10 blocks the phar: stream wrapper but not the uppercase PHAR: form, so a crafted archive path can trigger PHP unserialization of untrusted data. Because Archive_Tar is bundled with PHP and used by projects such as Drupal, any application extracting attacker-supplied archives is exposed to object injection.
Impact
An attacker who gets a malicious archive processed can deserialize arbitrary PHP objects, which typically leads to code execution or file manipulation in the context of the web server.
Attack surface
Reached locally per the CVSS vector (AV:L) but requires user interaction (UI:R), meaning a victim or application must process a crafted archive; no authentication is needed (PR:N). The flaw is in archive path handling, so any code path that extracts untrusted tar files is a candidate entry point.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 47 percent (98.8th percentile) and the GitHub issue reference is tagged Exploit, indicating public proof-of-concept material exists. No ransomware usage is documented.
What to do
- Upgrade Archive_Tar past 1.4.10 to the fixed release, and update PHP or Drupal packages that bundle it.
- Apply the vendor patches from Debian DSA-4817, the Fedora advisories and the Drupal SA-CORE-2020-013 notice.
- Avoid extracting untrusted tar archives, or validate and normalize archive member paths before extraction.
- Disable or restrict the phar stream wrapper where the application does not need it.
- Track the Gentoo GLSA 202101-23 guidance for affected Gentoo installs.
Detection
- Search application and web logs for archive upload or extraction requests containing PHAR: or phar: in filenames or paths.
- Monitor for unexpected PHP object instantiation or file writes immediately after archive extraction events.
- Inventory installed Archive_Tar, PHP and Drupal versions to find hosts still on 1.4.10 or earlier.
- Alert on outbound or file-system activity from the web server process following archive processing.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-28948 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28948), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.