StackRadar

CVE-2025-59343

High

Advisory

Published 24 Sept 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.006
44th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
125
of 17,781 indexed, latest versions
Container images
122
deployed by those charts
Fix available
1 of 1
affected package

tar-fs has a symlink validation bypass if destination directory is predictable with a specific tarball

Carried by container images the latest versions of 125 of 17,781 indexed charts deploy, on 122 images.

Affected packageAffected versionsFixed inImages
tar-fsnpm0.5.2, 1.12.0, 1.15.3, 1.16.2+12 more1.16.6, 2.1.4, 3.1.1122
OSV records
GHSA-vj76-c3g6-qr5v

Charts affected

125 by stars
ChartLatestAffected imagesRadar Score
krokicowboysysopVerified publisher6.1.01 of 5See more

kroki cowboysysop 6.1.0

1 of the 5 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
yuzutech/kroki-excalidraw:0.29.157917319ea70
tar-fs@3.0.5
3.1.1

Open the chart page →

6,743
n8nn8n0.23.01 of 1See more

n8n n8n 0.23.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
n8nio/n8n:1.33.1dd171d45102a
tar-fs@2.1.1
2.1.4

Open the chart page →

5,639
code-serverdeploy-code-server1.0.31 of 2See more

code-server deploy-code-server 1.0.3

1 of the 2 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
codercom/code-server:3.10.247605610ad8d
tar-fs@2.1.1
2.1.4

Open the chart page →

4,577
homarroben01Verified publisher1.4.01 of 1See more

homarr oben01 1.4.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/ajnart/homarr:0.16.0737ec361ed24
tar-fs@2.1.3
2.1.4

Open the chart page →

2,581
redisinsightheywood8-helm-chartsVerified publisher0.4.51 of 1See more

redisinsight heywood8-helm-charts 0.4.5

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
heywood8/redisinsight:2.28.00bc9ab313d37
tar-fs@2.1.1
2.1.4

Open the chart page →

2,828
redisinsight-secureredisinsight-secureVerified publisher1.0.21 of 1See more

redisinsight-secure redisinsight-secure 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
redis/redisinsight:2.68019fcf774631
tar-fs@2.1.1
2.1.4

Open the chart page →

1,721
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
tar-fs@2.1.1
2.1.4

Open the chart page →

5,251
backstagedeliveryheroVerified publisher0.1.151 of 2See more

backstage deliveryhero 0.1.15

1 of the 2 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tar-fs@2.0.1
2.1.4

Open the chart page →

8,213
wikijsgeek-cookbookVerified publisher6.4.21 of 1See more

wikijs geek-cookbook 6.4.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/wikijs:version-2.5.20158d377933678
tar-fs@2.1.1
2.1.4

Open the chart page →

5,946
karakeephelmforgeVerified publisher1.2.91 of 3See more

karakeep helmforge 1.2.9

1 of the 3 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.33.2b069e4307dec
tar-fs@2.1.3
2.1.4

Open the chart page →

9,460
librechatlibrechat1.8.101 of 3See more

librechat librechat 1.8.10

1 of the 3 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/danny-avila/librechat:v0.7.78c68abbe1cff
tar-fs@3.0.4
3.1.1

Open the chart page →

2,654
grafana-pdf-exporterwiremindVerified publisher2.1.11 of 1See more

grafana-pdf-exporter wiremind 2.1.1

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/wiremind/grafana-pdf-exporter:v1.7dbaa8527bf4c
tar-fs@3.0.4
3.1.1

Open the chart page →

9,746
code-serveralekcVerified publisher0.1.11 of 1See more

code-server alekc 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
linuxserver/code-server:4.10.1a5e43a05ae79
tar-fs@2.1.1
2.1.4

Open the chart page →

8,212
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
tar-fs@1.16.3
1.16.6

Open the chart page →

7,450
foremancontane-githubOfficialVerified publisher0.6.01 of 1See more

foreman contane-github 0.6.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
contane/foreman:0.5.2efb98bdcc4e9
tar-fs@3.0.8
3.1.1

Open the chart page →

1,152
calibregeek-cookbookVerified publisher5.4.21 of 1See more

calibre geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
linuxserver/calibre:version-v5.21.0a847b5b2d860
tar-fs@2.1.1
2.1.4

Open the chart page →

22,773
zwavejs2mqttgeek-cookbookVerified publisher5.4.21 of 1See more

zwavejs2mqtt geek-cookbook 5.4.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
tar-fs@2.1.1
2.1.4

Open the chart page →

3,476
kongakonga1.1.01 of 1See more

konga konga 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
tar-fs@1.15.3
1.16.6

Open the chart page →

5,209
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
tar-fs@2.1.1
2.1.4

Open the chart page →

2,635
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
tar-fs@2.0.0
2.1.4

Open the chart page →

18,517
n8none-acre-fundVerified publisher0.1.521 of 3See more

n8n one-acre-fund 0.1.52

1 of the 3 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
n8nio/n8n:0.212.0a9195bc499a3
tar-fs@2.1.1
2.1.4

Open the chart page →

7,776
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar-fs@2.1.1
2.1.4

Open the chart page →

24,488
predatorzooz1.7.01 of 1See more

predator zooz 1.7.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
zooz/predator:1.6f491d1f7a865
tar-fs@1.16.3
1.16.6

Open the chart page →

2,851
soarv113assist-iot-cybersecurity-monitoring-soar0.1.31 of 5See more

soarv113 assist-iot-cybersecurity-monitoring-soar 0.1.3

1 of the 5 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
tar-fs@2.1.1
2.1.4

Open the chart page →

17,896
dltbrokerassist-iot-distributed-broker0.2.01 of 9See more

dltbroker assist-iot-distributed-broker 0.2.0

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
tar-fs@2.1.1
2.1.4

Open the chart page →

77,706
dltloggingassist-iot-logging-auditing0.2.01 of 9See more

dltlogging assist-iot-logging-auditing 0.2.0

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
tar-fs@2.1.1
2.1.4

Open the chart page →

77,687
actualbeluga-cloudVerified publisher2.0.01 of 1See more

actual beluga-cloud 2.0.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/beluga-cloud/actual/actualserver:23.12.1c8a0d5ec5a12
tar-fs@2.1.1
2.1.4

Open the chart page →

1,262
data-fairdata354-helmVerified publisher1.1.22 of 12See more

data-fair data354-helm 1.1.2

2 of the 12 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/data-fair/data-fair:3cc9498b64b5b
tar-fs@2.1.1
2.1.4
ghcr.io/data-fair/notify:3c739b74dabb0
tar-fs@2.1.2
2.1.4

Open the chart page →

38,346
iobrokereugen0.2.61 of 1See more

iobroker eugen 0.2.6

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/buanet/iobroker:v9.1.2ca7dc7362968
tar-fs@3.0.6
3.1.1

Open the chart page →

11,458
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
tar-fs@2.1.1
2.1.4

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
tar-fs@2.1.1
2.1.4

Open the chart page →

15,653
zigbee2mqttgeek-cookbookVerified publisher9.4.21 of 1See more

zigbee2mqtt geek-cookbook 9.4.2

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
tar-fs@2.1.1
2.1.4

Open the chart page →

2,173
elasticinseefrlab2.2.01 of 2See more

elastic inseefrlab 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
library/kibana:7.17.3e2e2031c15be
tar-fs@2.0.0
2.1.4

Open the chart page →

17,284
kenerkenerVerified publisher0.2.01 of 1See more

kener kener 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
rajnandan1/kener:3.2.1930407afca731
tar-fs@2.1.2
2.1.4

Open the chart page →

5,228
food-managermoreillonVerified publisher0.5.01 of 2See more

food-manager moreillon 0.5.0

1 of the 2 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
moreillon/food-manager:lateste8fd856e593d
tar-fs@2.1.1
2.1.4

Open the chart page →

13,738
portraitportraitVerified publisher0.2.132 of 8See more

portrait portrait 0.2.13

2 of the 8 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
codercom/code-server:4.11.0-debian1e2cc688008e
tar-fs@2.1.1
2.1.4
treskon/portrait-ui:DEV-lateste7970783bc8d
tar-fs@3.0.9
3.1.1

Open the chart page →

31,844
kibanaromanow-helm-chartsVerified publisher1.7.11 of 1See more

kibana romanow-helm-charts 1.7.1

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
library/kibana:7.17.8c5781ba340ef
tar-fs@2.1.1
2.1.4

Open the chart page →

6,879
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
tar-fs@2.1.2
2.1.4

Open the chart page →

2,823
karakeepself-hosters-by-nightVerified publisher2.5.11 of 1See more

karakeep self-hosters-by-night 2.5.1

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/karakeep-app/karakeep:0.27.1abd7d6b11b1b
tar-fs@2.1.3
2.1.4

Open the chart page →

5,213
stornxstornxVerified publisher1.1.11 of 9See more

stornx stornx 1.1.1

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
alazidis/stornx:1.1.1602d4f7f090c
tar-fs@3.0.8
3.1.1

Open the chart page →

11,574
wikiwenerme2.2.01 of 2See more

wiki wenerme 2.2.0

1 of the 2 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
requarks/wiki:latest68f0d1848261
tar-fs@2.1.1
2.1.4

Open the chart page →

3,833
akto-mini-testingakto1.45.71 of 5See more

akto-mini-testing akto 1.45.7

1 of the 5 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
public.ecr.aws/aktosecurity/akto-puppeteer-replay:1.49.4_latestf1c5763d565e
tar-fs@2.1.1
2.1.4

Open the chart page →

6,486
akto-source-code-analyserakto0.1.51 of 3See more

akto-source-code-analyser akto 0.1.5

1 of the 3 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
tar-fs@3.0.5
3.1.1

Open the chart page →

4,880
dltkvassist-iot-data-integrity-verification0.2.01 of 9See more

dltkv assist-iot-data-integrity-verification 0.2.0

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.0.0e36a8922fa0c
tar-fs@2.1.1
2.1.4

Open the chart page →

77,706
dltflassist-iot-dlt-based-fl0.2.01 of 9See more

dltfl assist-iot-dlt-based-fl 0.2.0

1 of the 9 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
assistiot/dlt_api:2.1.0c8a170683be7
tar-fs@2.1.1
2.1.4

Open the chart page →

77,706
openapiassist-iot-open-api-management0.2.21 of 6See more

openapi assist-iot-open-api-management 0.2.2

1 of the 6 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
pantsel/konga:latestc8172b75607d
tar-fs@1.15.3
1.16.6

Open the chart page →

18,277
audiobookshelfbdclark-helm-chartsVerified publisher0.1.41 of 1See more

audiobookshelf bdclark-helm-charts 0.1.4

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
tar-fs@2.1.2
2.1.4

Open the chart page →

1,722
mx-apibicarus-labs0.1.01 of 4See more

mx-api bicarus-labs 0.1.0

1 of the 4 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar-fs@2.1.1
2.1.4

Open the chart page →

4,455
registry-uibryanalves0.2.01 of 1See more

registry-ui bryanalves 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
konradkleine/docker-registry-frontend:v2181aad54ee64
tar-fs@0.5.2
1.16.6

Open the chart page →

4,069
cross-seedcfi20176.13.61 of 1See more

cross-seed cfi2017 6.13.6

1 of the 1 container images this version deploys carry CVE-2025-59343.

Container imageDigestPackageFixed in
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
tar-fs@2.1.2
2.1.4

Open the chart page →

1,338

Container images carrying it

122 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/advplyr/audiobookshelf:2.36.0180acad33d69
tar-fs@2.1.2
2.1.4
4
assistiot/dlt_api:2.0.0e36a8922fa0c
tar-fs@2.1.1
2.1.4
3
pantsel/konga:latestc8172b75607d
tar-fs@1.15.3
1.16.6
3
rcdelacruz/my-strapi-app:js-amd6438007f358355
tar-fs@2.1.1
2.1.4
3
governify/assets-manager:v1.4.12987672448c7
tar-fs@2.1.1
2.1.4
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
tar-fs@2.1.1
2.1.4
2
l7mp/kurento-one2one-call-server:latestfd2b2d06fff6
tar-fs@1.16.2
1.16.6
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
tar-fs@2.0.1
2.1.4
2
rajnandan1/kener:3.2.1930407afca731
tar-fs@2.1.2
2.1.4
2
redis/redis-stack:7.2.0-v91c5f43fddcdd
tar-fs@2.1.1
2.1.4
2
requarks/wiki:2:latest68f0d1848261
tar-fs@2.1.1
2.1.4
2
speckle/speckle-preview-service:2.18.11-branch.testing2.88634-335d469:2.18.12-branch.testing3.88744-f55b3414bd113093583
tar-fs@2.1.1
2.1.4
2
ghcr.io/cross-seed/cross-seed:6.13.381afafdd96a5
tar-fs@2.1.2
2.1.4
2
activepieces/activepieces:0.23.0c26188b44e62
tar-fs@2.1.1
2.1.4
1
actualbudget/actual-server:25.3.158fecd9088b7
tar-fs@2.1.1
2.1.4
1
aktosecurity/akto-puppeteer-replay:doom_latest853e37321e6e
tar-fs@3.0.5
3.1.1
1
alazidis/stornx:1.1.1602d4f7f090c
tar-fs@3.0.8
3.1.1
1
assistiot/cybersecurity-monitoring_ir-kbn:latest0570b27bb7c2
tar-fs@2.1.1
2.1.4
1
assistiot/dlt_api:2.1.0c8a170683be7
tar-fs@2.1.1
2.1.4
1
automatischio/automatisch:0.15.03bace7a12d5f
tar-fs@2.1.1
2.1.4
1
bicarus/mx-api-service:1.0.2-hf1dab88659ae3b
tar-fs@2.1.1
2.1.4
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
tar-fs@2.1.1
2.1.4
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
tar-fs@3.0.6
3.1.1
1
coderaiser/cloudcmd:16.6.1b34a9775c7ce
tar-fs@2.1.1
2.1.4
1
codercom/code-server:4.11.0-debian1e2cc688008e
tar-fs@2.1.1
2.1.4
1
codercom/code-server:3.10.247605610ad8d
tar-fs@2.1.1
2.1.4
1
codetogether/codetogether:latest4348c8a38752
tar-fs@1.16.3
1.16.6
1
contane/foreman:0.5.2efb98bdcc4e9
tar-fs@3.0.8
3.1.1
1
countly/api:25.05.4f4cc7447c4f5
tar-fs@2.1.1
2.1.4
1
countly/countly-server:25.05.4e3c238248f99
tar-fs@2.1.1
2.1.4
1
countly/frontend:25.05.42acbc11499b6
tar-fs@2.1.1
2.1.4
1
dacinfomotion/h2p:latest68fa393b472c
tar-fs@3.0.4
3.1.1
1
directus/directus:11.1.0e3c8bb975350
tar-fs@2.1.1
2.1.4
1
enketo/enketo-express:3.0.4dcad9c2273f6
tar-fs@2.0.0
2.1.4
1
ethereumoptimism/data-transport-layer:0.5.56e07968a0e686
tar-fs@2.1.1
2.1.4
1
fallenbagel/jellyseerr:latest4538137bc5af
tar-fs@2.1.2
2.1.4
1
getferdi/ferdi-server:1.3.26e620b85afaa
tar-fs@1.16.3
1.16.6
1
heywood8/redisinsight:2.28.00bc9ab313d37
tar-fs@2.1.1
2.1.4
1
ianw/quickchart:v1.7.1dc49dd460c37
tar-fs@2.1.1
2.1.4
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
tar-fs@1.12.0
1.16.6
1
ibmcom/microclimate-portal:latested5505e5c7ec
tar-fs@1.12.0
1.16.6
1
jakowenko/double-take:1.6.0b858bac9e32a
tar-fs@2.1.1
2.1.4
1
konradkleine/docker-registry-frontend:v2181aad54ee64
tar-fs@0.5.2
1.16.6
1
library/ghost:4.37.0767230c0f263
tar-fs@2.1.1
2.1.4
1
library/ghost:5.79.083f7bf209844
tar-fs@3.0.4
3.1.1
1
library/kibana:7.17.150172f1c538e7
tar-fs@3.0.4
3.1.1
1
library/kibana:8.18.004c0fc150f3a
tar-fs@3.0.8
3.1.1
1
library/kibana:7.17.8c5781ba340ef
tar-fs@2.1.1
2.1.4
1
library/kibana:7.17.3e2e2031c15be
tar-fs@2.0.0
2.1.4
1
linuxserver/calibre:version-v5.21.0a847b5b2d860
tar-fs@2.1.1
2.1.4
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.