Filename Hiding Vulnerability in tar for BusyBox by BusyBox
CVE-2025-46394
3.2LOW
What is CVE-2025-46394?
A vulnerability exists in the tar component of BusyBox up to version 1.37.0, allowing malicious actors to obscure filenames within TAR archives using terminal escape sequences. This deceptive practice can hinder users from accurately assessing the contents of an archive, raising significant security concerns regarding file integrity and transparency. Users and administrators should take appropriate measures to mitigate this risk, especially those relying on BusyBox for handling TAR files.
Affected Version(s)
BusyBox 0 <= 1.37.0
