Goal Reached Thanks to every supporter โ€” we hit 100%!

Goal: 1000 CNY ยท Raised: 1359 CNY

100%

CVE-2021-32804 โ€” AI Deep Analysis Summary

CVSS 8.2 ยท High

Q1What is this vulnerability? (Essence + Consequences)

๐Ÿšจ **Essence**: A Path Traversal vulnerability in `node-tar` (npm package). ๐Ÿ“ฆ **Consequences**: Due to insufficient absolute path cleaning, attackers can create or overwrite arbitrary files on the system.โ€ฆ

Q2Root Cause? (CWE/Flaw)

๐Ÿ›ก๏ธ **Root Cause**: CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). ๐Ÿ› **Flaw**: The library fails to properly sanitize absolute paths during extraction, allowing directory traversal attacks.

Q3Who is affected? (Versions/Components)

๐Ÿ‘ฅ **Affected**: Users of the `node-tar` npm package. ๐Ÿ“‰ **Vendor**: npm. โš ๏ธ **Note**: Since `npm` itself uses `node-tar`, the npm tool is also indirectly affected by this vulnerability.

Q4What can hackers do? (Privileges/Data)

๐Ÿ•ต๏ธ **Hackers Can**: Create arbitrary files or overwrite existing ones. ๐Ÿ“‚ **Privileges**: Local access required, but can lead to system compromise.โ€ฆ

Q5Is exploitation threshold high? (Auth/Config)

๐Ÿ”“ **Threshold**: Low to Medium. ๐Ÿ–ฑ๏ธ **Requirements**: Local Access (AV:L), Low Complexity (AC:L), No Privileges Required (PR:N), but User Interaction (UI:R) is needed (e.g., clicking a malicious link or running a command)โ€ฆ

Q6Is there a public Exp? (PoC/Wild Exploitation)

๐Ÿ”ฅ **Public Exploit**: YES. ๐Ÿ“‚ **PoC Available**: A GitHub repository (`yamory/CVE-2021-32804`) provides Docker-based reproduction steps. ๐Ÿ’ป **Proof**: Demonstrates overwriting `.bashrc` to execute commands upon `su node`.

Q7How to self-check? (Features/Scanning)

๐Ÿ” **Self-Check**: Scan for `node-tar` versions in your `package-lock.json` or `node_modules`. ๐Ÿ› ๏ธ **Feature**: Check if your app extracts tarballs from untrusted sources.โ€ฆ

Q8Is it fixed officially? (Patch/Mitigation)

โœ… **Fixed**: YES. ๐Ÿ“ **Patch**: Official commit `1f036ca23f64a547bdd6c79c1a44bc62e8115da4` on GitHub addresses the issue. ๐Ÿ”„ **Action**: Update `node-tar` to the patched version immediately.

Q9What if no patch? (Workaround)

๐Ÿšง **No Patch?**: Avoid extracting untrusted tar files. ๐Ÿ›‘ **Mitigation**: Implement strict path validation before extraction.โ€ฆ

Q10Is it urgent? (Priority Suggestion)

๐Ÿšจ **Urgency**: HIGH. ๐Ÿ”ด **Priority**: Critical for Node.js developers. โณ **Reason**: CVSS Score indicates High impact (C:H, I:H). Since npm is widely used, the attack surface is broad. Patch ASAP!