Unsafe symbolic links during archive extraction

Unsafe symbolic-link creation during archive extraction

Description

Creating archive links with os.Symlink without validating both the entry name and link target can create links outside the extraction directory.

Potential impact

  • Later extraction may follow a link and overwrite files outside the destination.
  • Configuration or executable files may be modified.

Remediation

  • Reject symbolic-link entries by default, or allow only explicitly approved cases.
  • Validate that both the link name and its target stay within the extraction root.

Examples

Before

go
target := filepath.Join(dest, hdr.Name)
_ = os.Symlink(hdr.Linkname, target)

After

go
package example

import (
    "archive/tar"
    "fmt"
)

func rejectArchiveLinks(hdr *tar.Header) error {
    switch hdr.Typeflag {
    case tar.TypeSymlink, tar.TypeLink:
        return fmt.Errorf("archive links are not allowed: %q", hdr.Name)
    }
    return nil
}

Explanation:

  • Before: Unvalidated entry names and targets can use existing links or .. paths to create links pointing outside the extraction root.
  • After: Explicitly reject symbolic-link and hard-link entries. Using only filepath.Base(hdr.Linkname) is insufficient because a target of .. can remain unchanged.

References