StackRadar

CVE-2024-12905

High

Advisory

Published 27 Mar 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.022
82nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
101
of 17,781 indexed, latest versions
Container images
101
deployed by those charts
Fix available
1 of 1
affected package

tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File

Carried by container images the latest versions of 101 of 17,781 indexed charts deploy, on 101 images.

Affected packageAffected versionsFixed inImages
tar-fsnpm0.5.2, 1.12.0, 1.15.3, 1.16.2+7 more1.16.4, 2.1.2, 3.0.7101
OSV records
GHSA-pq67-2wwv-3xjx

Charts affected

101 by stars
ChartLatestAffected imagesRadar Score
wikiwikijs3.0.01 of 2See more

wiki wikijs 3.0.0

1 of the 2 container images this version deploys carry CVE-2024-12905.

Container imageDigestPackageFixed in
requarks/wiki:268f0d1848261
tar-fs@2.1.1
2.1.2

Open the chart page →

5,459

Container images carrying it

101 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
assistiot/dlt_api:2.0.0e36a8922fa0c
tar-fs@2.1.1
2.1.2
3
pantsel/konga:latestc8172b75607d
tar-fs@1.15.3
1.16.4
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
tar-fs@2.1.1
2.1.2
3
governify/assets-manager:v1.4.12987672448c7
tar-fs@2.1.1
2.1.2
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
tar-fs@2.1.1
2.1.2
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tar-fs@1.16.2
1.16.4
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tar-fs@2.0.1
2.1.2
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
tar-fs@2.1.1
2.1.2
2
requarks/wiki:2:latest68f0d1848261
tar-fs@2.1.1
2.1.2
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
tar-fs@2.1.1
2.1.2
2
activepieces/activepieces:0.23.0c26188b44e62
tar-fs@2.1.1
2.1.2
1
actualbudget/actual-server:25.3.158fecd9088b7
tar-fs@2.1.1
2.1.2
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
tar-fs@3.0.5
3.0.7
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
tar-fs@2.1.1
2.1.2
1
assistiot/dlt_api:2.1.0c8a170683be7
tar-fs@2.1.1
2.1.2
1
automatischio/automatisch:0.15.03bace7a12d5f
tar-fs@2.1.1
2.1.2
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar-fs@2.1.1
2.1.2
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar-fs@2.1.1
2.1.2
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
tar-fs@3.0.6
3.0.7
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar-fs@2.1.1
2.1.2
1
codercom/code-server:4.11.0-debian1e2cc688008e
tar-fs@2.1.1
2.1.2
1
codercom/code-server:3.10.247605610ad8d
tar-fs@2.1.1
2.1.2
1
codetogether/codetogether:latest4348c8a38752
tar-fs@1.16.3
1.16.4
1
countly/api:25.05.4f4cc7447c4f5
tar-fs@2.1.1
2.1.2
1
countly/countly-server:25.05.4e3c238248f99
tar-fs@2.1.1
2.1.2
1
countly/frontend:25.05.42acbc11499b6
tar-fs@2.1.1
2.1.2
1
dacinfomotion/h2p:latest68fa393b472c
tar-fs@3.0.4
3.0.7
1
directus/directus:11.1.0e3c8bb975350
tar-fs@2.1.1
2.1.2
1
enketo/enketo-express:3.0.4dcad9c2273f6
tar-fs@2.0.0
2.1.2
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tar-fs@2.1.1
2.1.2
1
getferdi/ferdi-server:1.3.26e620b85afaa
tar-fs@1.16.3
1.16.4
1
heywood8/redisinsight:2.28.00bc9ab313d37
tar-fs@2.1.1
2.1.2
1
ianw/quickchart:v1.7.1dc49dd460c37
tar-fs@2.1.1
2.1.2
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
tar-fs@1.12.0
1.16.4
1
ibmcom/microclimate-portal:latested5505e5c7ec
tar-fs@1.12.0
1.16.4
1
jakowenko/double-take:1.6.0b858bac9e32a
tar-fs@2.1.1
2.1.2
1
konradkleine/docker-registry-frontend:v2181aad54ee64
tar-fs@0.5.2
1.16.4
1
library/ghost:4.37.0767230c0f263
tar-fs@2.1.1
2.1.2
1
library/ghost:5.79.083f7bf209844
tar-fs@3.0.4
3.0.7
1
library/kibana:7.17.150172f1c538e7
tar-fs@3.0.4
3.0.7
1
library/kibana:7.17.8c5781ba340ef
tar-fs@2.1.1
2.1.2
1
library/kibana:7.17.3e2e2031c15be
tar-fs@2.0.0
2.1.2
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
tar-fs@2.1.1
2.1.2
1
linuxserver/cloud9:latest45c5fe102ff3
tar-fs@1.16.3
1.16.4
1
linuxserver/code-server:4.10.1a5e43a05ae79
tar-fs@2.1.1
2.1.2
1
markdegroot/unifi-protect-arm64:latestd8445f2a0de6
tar-fs@2.1.1
2.1.2
1
mintproject/ensemble-manager:d5656dbc01623e291564d2894c72f0e7cb2408f4222e3b941a36
tar-fs@2.0.1
2.1.2
1
misskey/misskey:12.110.1e08b7c478093
tar-fs@2.1.1
2.1.2
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
tar-fs@2.1.1
2.1.2
1
moreillon/food-manager:lateste8fd856e593d
tar-fs@2.1.1
2.1.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.