Reference INC2833242: ----- There's an issue in https://github.com/mholt/archiver/ (version 3). v4 is not affected, as it doesn't support this functionality. It's a path traversal when unpacking a specially crafted tar archive. I've originally reported this in Syft, but the underlying issue is in this library.