← Vulnerability feed

Vulnerability record · CVE-2021-32610 · published 30 July 2021

CVE-2021-32610: Archive_Tar symlink path traversal outside extraction directory

Php · Archive Tar

Archive_Tar before 1.4.14 allows symlinks in an archive to point to targets outside the extraction directory, a link-following flaw distinct from CVE-2020-36193. Because the library is used by PHP applications and frameworks such as Drupal to unpack untrusted archives, a crafted tarball can write or overwrite files outside the intended destination.

7.1 CVSS 3.1 High EPSS 73% · top 0.5% CWE-59 · Link following
7.1CVSS 3.1 base score, v2 3.6
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
18References
17 Jun 2026Last modified by NVD

Description

In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 7.1 high severity with a very high EPSS score, though exploitation requires local access and no KEV listing or public exploit reference is present.

What it is

Archive_Tar before 1.4.14 allows symlinks in an archive to point to targets outside the extraction directory, a link-following flaw distinct from CVE-2020-36193. Because the library is used by PHP applications and frameworks such as Drupal to unpack untrusted archives, a crafted tarball can write or overwrite files outside the intended destination.

Impact

An attacker who can supply a crafted archive can cause files to be written outside the extraction root, potentially overwriting sensitive files or planting content that leads to code execution in the context of the extracting process.

Attack surface

Reached locally per the CVSS vector (AV:L, PR:L, UI:N), meaning the attacker needs some existing access or ability to place an archive where the application extracts it; no user interaction is required. The description does not specify a remote vector, so remote reachability depends on how the consuming application exposes archive extraction.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.73377, 99.4th percentile), indicating elevated likelihood of attempted exploitation. References are patch, release-note and advisory links only; no public exploit reference is included in the record.

What to do

  • Upgrade Archive_Tar to 1.4.14 or later, or apply the vendor patches referenced in the advisory.
  • Update dependent platforms (Debian, Fedora, Drupal) to the fixed package versions listed in their advisories.
  • Avoid extracting untrusted archives with elevated privileges and extract into a dedicated, non-sensitive directory.
  • Where feasible, validate or reject archives containing symlinks before extraction.
  • Restrict write access of the extracting process to the intended destination directory.

Detection

  • Monitor for file creation or modification outside expected extraction directories by PHP processes using Archive_Tar.
  • Alert on symlinks created during archive extraction that resolve outside the extraction root.
  • Audit application logs for extraction of user-supplied tarballs and correlate with unexpected file writes.
  • Track Archive_Tar versions in deployed PHP applications and dependencies to find instances below 1.4.14.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755 PatchThird Party Advisory
https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f PatchThird Party Advisory
https://github.com/pear/Archive_Tar/releases/tag/1.4.14 Release NotesThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/07/msg00023.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAODVMHGL5MHQWQAQTXQ7G7
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G5LTY6COQYNMMHQJ3QIOJHE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7
https://www.drupal.org/sa-core-2021-004 Third Party Advisory
https://github.com/pear/Archive_Tar/commit/7789ebb2f34f9e4adb3a4152ad0d1548930a9755 PatchThird Party Advisory
https://github.com/pear/Archive_Tar/commit/b5832439b1f37331fb4f87e67fe4f PatchThird Party Advisory
https://github.com/pear/Archive_Tar/releases/tag/1.4.14 Release NotesThird Party Advisory
https://lists.debian.org/debian-lts-announce/2021/07/msg00023.html Mailing ListThird Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/42GPGVVFTLJYAKRI75IVB5R
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CAODVMHGL5MHQWQAQTXQ7G7
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/G5LTY6COQYNMMHQJ3QIOJHE
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VJQQYDAOWHD6RDITDRPHFW7
https://www.drupal.org/sa-core-2021-004 Third Party Advisory

Track CVE-2021-32610 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2024-4577PHP-CGI on Windows argument injection leads to remote code executionPHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windo…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2021-32610), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.