Description
Creating archive links with os.Symlink without validating both the entry name and link target can create links outside the extraction directory.
Potential impact
- Later extraction may follow a link and overwrite files outside the destination.
- Configuration or executable files may be modified.
Remediation
- Reject symbolic-link entries by default, or allow only explicitly approved cases.
- Validate that both the link name and its target stay within the extraction root.
Examples
Before
go
target := filepath.Join(dest, hdr.Name)
_ = os.Symlink(hdr.Linkname, target)
After
go
package example
import (
"archive/tar"
"fmt"
)
func rejectArchiveLinks(hdr *tar.Header) error {
switch hdr.Typeflag {
case tar.TypeSymlink, tar.TypeLink:
return fmt.Errorf("archive links are not allowed: %q", hdr.Name)
}
return nil
}
Explanation:
- Before: Unvalidated entry names and targets can use existing links or
..paths to create links pointing outside the extraction root. - After: Explicitly reject symbolic-link and hard-link entries. Using only
filepath.Base(hdr.Linkname)is insufficient because a target of..can remain unchanged.