PEAR Archive_Tar through version 1.4.10 inadequately sanitizes archive entry filenames. Its sanitization addresses PHAR-related paths but does not block other PHP stream-wrapper paths, permitting a crafted archive to cause file overwrites when processed. In Drupal deployments that permit and process specified tar-based uploads from untrusted users, the affected Archive_Tar vulnerabilities can lead to arbitrary PHP code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module (archive_tar_arb_file_write.rb) that exploits CVE-2020-28949, a vulnerability in PEAR Archive_Tar <= 1.4.10. The exploit leverages improper validation of file stream wrappers in filenames, allowing an attacker to craft a malicious tar archive that, when processed by a vulnerable system, writes an attacker-controlled file to an arbitrary location on disk. The file is written with the permissions of the PHP process user. The module allows the attacker to specify the file path (default: /tmp/msf.php) and the content (typically a PHP payload). The exploit is weaponized, as it is part of the Metasploit framework and supports customizable payloads. The only file in the repository is the Metasploit module itself, written in Ruby.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability affecting the php-pecl-apcu SRPM/package on CIQ LTS 8.6 and Rocky Linux 8.6 systems covered by CIQ advisory ciqsa-2026_0003.
An Archive_Tar improper filename-sanitization vulnerability that can permit file overwrites during archive extraction or processing.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.