Vulnerability Management

Widespread Rust library forks exposed to remote code execution risk

Header graphic features a laptop with a red warning triangle and alert icons, dark background with streaming green code. It suggests concepts of cybersecurity threats, hacking, and system errors.

CyberScoop reports that an abandoned Rust code library async-tar, which has been reused in several forks, contains a major security flaw, tracked as CVE-2025-62518, that allows remote code execution through file overwriting and affects many other projects built from it.

Such an issue, dubbed TARmageddon, was discovered during internal testing on Aug. 21, with patches issued the following day, according to researchers from the cybersecurity firm Edera. The company worked to fix the problem across several forks before publicly disclosing the flaw on Tuesday.

Edera co-founder and Chief Technology Officer Alex Zenla described the flaw as "a textbook case of the open-source abandonware crisis," explaining that it began in early code then later copied into newer versions after the original project stopped getting updates.

Zenla also said that the affected code is used for archiving processing throughout the Rust ecosystem and warned that "the most concerning part is unawareness."

While Rust is considered a secure language, Zenla noted that the case shows that even safer programming environments can still face risks from old, unmaintained code.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds