← Vulnerability feed

Vulnerability record · CVE-2020-36193 · published 18 January 2021

CVE-2020-36193: PEAR Archive_Tar path traversal via symlink handling

Php · Archive Tar

Tar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory via directory traversal. It is a related issue to CVE-2020-28948 and affects PHP applications that extract untrusted tar archives, including Drupal and Linux distributions shipping the library.

7.5 CVSS 3.1 High CISA KEV since 25 Aug 2022 EPSS 71% · top 0.6% CWE-22 · Path traversalCWE-59 · Link following
7.5CVSS 3.1 base score, v2 5.0
71%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
21References
17 Jun 2026Last modified by NVD

Description

Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a very high EPSS score and a network-reachable, no-authentication vector, though impact is limited to integrity.

What it is

Tar.php in Archive_Tar through 1.4.11 fails to adequately check symbolic links, allowing write operations to escape the intended extraction directory via directory traversal. It is a related issue to CVE-2020-28948 and affects PHP applications that extract untrusted tar archives, including Drupal and Linux distributions shipping the library.

Impact

An attacker can write files outside the intended extraction path, potentially overwriting application or system files. The CVSS vector shows no confidentiality or availability impact, only high integrity impact.

Attack surface

Reached over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS vector, meaning any code path that extracts an attacker-supplied tar archive is exposed. The record does not specify the exact calling application or endpoint.

Exploitation

CVE-2020-36193 is listed in CISA KEV with a due date of 2022-09-15, indicating known exploitation in the wild, and EPSS gives a 30-day probability of 0.706 (99.4th percentile). No ransomware campaign use is documented in the record.

What to do

  • Upgrade Archive_Tar past 1.4.11 using the upstream patch commit, and apply the vendor updates referenced by Debian, Fedora, Gentoo and Drupal advisories.
  • Update Drupal core and any PHP application bundling Archive_Tar to the fixed release.
  • Avoid extracting tar archives from untrusted or user-supplied sources, or extract them in a sandboxed directory with no write access to sensitive paths.
  • Validate and normalize archive entry paths and reject entries containing traversal sequences or symlinks before extraction.

Detection

  • Monitor for file writes outside expected extraction directories, especially new or modified files in web roots, config directories or cron paths.
  • Alert on tar extraction processes creating symlinks that point outside the target directory.
  • Audit application logs for archive upload or extraction events followed by unexpected file creation or modification.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-36193 to the Known Exploited Vulnerabilities catalog on 25 August 2022 as "PEAR Archive_Tar Improper Link Resolution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 September 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916 Patch
https://lists.debian.org/debian-lts-announce/2021/01/msg00018.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/04/msg00007.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FOZNK4FIIV7FSFCJNNFWMJZ Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7 Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKD5WEFA4WT6AVTMRAYBNXZ Broken Link
https://security.gentoo.org/glsa/202101-23 Third Party Advisory
https://www.debian.org/security/2021/dsa-4894 Third Party Advisory
https://www.drupal.org/sa-core-2021-001 Third Party Advisory
https://github.com/pear/Archive_Tar/commit/cde460582ff389404b5b3ccb59374e9b389de916 Patch
https://lists.debian.org/debian-lts-announce/2021/01/msg00018.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/04/msg00007.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FOZNK4FIIV7FSFCJNNFWMJZ Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7 Broken Link
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YKD5WEFA4WT6AVTMRAYBNXZ Broken Link
https://security.gentoo.org/glsa/202101-23 Third Party Advisory
https://www.debian.org/security/2021/dsa-4894 Third Party Advisory
https://www.drupal.org/sa-core-2021-001 Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-36193 US Government Resource

Track CVE-2020-36193 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-9082Drupal core SQL injection in unauthenticated request pathDrupal core contains a SQL injection flaw (CWE-89) caused by improper neutralization of special elements in SQL commands. It affects multiple core br…KEVEPSS 16%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed

Source: NIST National Vulnerability Database (record CVE-2020-36193), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.