Vulnerability record · CVE-2020-36193 · published 18 January 2021
CVE-2020-36193: PEAR Archive_Tar path traversal via symlink handling
Php · Archive Tar
Tar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory via directory traversal. It is a related issue to CVE-2020-28948 and affects PHP applications that extract untrusted tar archives, including Drupal and Linux distributions shipping the library.
Description
Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Automated analysis
high priorityIt is in CISA KEV with a very high EPSS score and a network-reachable, no-authentication vector, though impact is limited to integrity.
What it is
Tar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory via directory traversal. It is a related issue to CVE-2020-28948 and affects PHP applications that extract untrusted tar archives, including Drupal and Linux distributions shipping the library.
Impact
An attacker can write files outside the intended extraction path, potentially overwriting application or system files. The CVSS vector shows no confidentiality or availability impact, only high integrity impact.
Attack surface
Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS vector, meaning any code path that extracts an attacker-supplied tar archive is exposed. The record does not specify the exact calling application or endpoint.
Exploitation
CVE-2020-36193 is listed in CISA KEV with a due date of 2022-09-15, indicating known exploitation in the wild, and EPSS gives a 30-day probability of 0.706 (99.4th percentile). No ransomware campaign use is documented in the record.
What to do
- Upgrade Archive_Tar past 1.4.11 using the upstream patch commit, and apply the vendor updates referenced by Debian, Fedora, Gentoo and Drupal advisories.
- Update Drupal core and any PHP application bundling Archive_Tar to the fixed release.
- Avoid extracting tar archives from untrusted or user-supplied sources, or extract them in a sandboxed directory with no write access to sensitive paths.
- Validate and normalize archive entry paths and reject entries containing traversal sequences or symlinks before extraction.
Detection
- Monitor for file writes outside expected extraction directories, especially new or modified files in web roots, config directories or cron paths.
- Alert on tar extraction processes creating symlinks that point outside the target directory.
- Audit application logs for archive upload or extraction events followed by unexpected file creation or modification.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2020-36193 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "PEAR Archive_Tar Improper Link Resolution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-36193 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-36193), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.