Vulnerability record · CVE-2021-32610 · published 30 July 2021
CVE-2021-32610: Archive_Tar symlink path traversal outside extraction directory
Php · Archive Tar
Archive_Tar before 1.4.14 allows symlinks in an archive to point to targets outside the extraction directory, a link-following flaw distinct from CVE-2020-36193. Because the library is used by PHP applications and frameworks such as Drupal to unpack untrusted archives, a crafted tarball can write or overwrite files outside the intended destination.
Description
In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Automated analysis
high priorityCVSS 7.1 high severity with a very high EPSS score, though exploitation requires local access and no KEV listing or public exploit reference is present.
What it is
Archive_Tar before 1.4.14 allows symlinks in an archive to point to targets outside the extraction directory, a link-following flaw distinct from CVE-2020-36193. Because the library is used by PHP applications and frameworks such as Drupal to unpack untrusted archives, a crafted tarball can write or overwrite files outside the intended destination.
Impact
An attacker who can supply a crafted archive can cause files to be written outside the extraction root, potentially overwriting sensitive files or planting content that leads to code execution in the context of the extracting process.
Attack surface
Reached locally per the CVSS vector (AV:L, PR:L, UI:N), meaning the attacker needs some existing access or ability to place an archive where the application extracts it; no user interaction is required. The description does not specify a remote vector, so remote reachability depends on how the consuming application exposes archive extraction.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.73377, 99.4th percentile), indicating elevated likelihood of attempted exploitation. References are patch, release-note and advisory links only; no public exploit reference is included in the record.
What to do
- Upgrade Archive_Tar to 1.4.14 or later, or apply the vendor patches referenced in the advisory.
- Update dependent platforms (Debian, Fedora, Drupal) to the fixed package versions listed in their advisories.
- Avoid extracting untrusted archives with elevated privileges and extract into a dedicated, non-sensitive directory.
- Where feasible, validate or reject archives containing symlinks before extraction.
- Restrict write access of the extracting process to the intended destination directory.
Detection
- Monitor for file creation or modification outside expected extraction directories by PHP processes using Archive_Tar.
- Alert on symlinks created during archive extraction that resolve outside the extraction root.
- Audit application logs for extraction of user-supplied tarballs and correlate with unexpected file writes.
- Track Archive_Tar versions in deployed PHP applications and dependencies to find instances below 1.4.14.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-32610 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32610), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.