Access of Resource Using Incompatible Type ('Type Confusion') Affecting pixi package, versions <0.57.0-r1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.02% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Access of Resource Using Incompatible Type ('Type Confusion') vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-CHAINGUARDLATEST-PIXI-13653972
  • published22 Oct 2025
  • disclosed21 Oct 2025

Introduced: 21 Oct 2025

NewCVE-2025-62518  (opens in a new tab)
CWE-843  (opens in a new tab)

How to fix?

Upgrade Chainguard pixi to version 0.57.0-r1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream pixi package and not the pixi package as distributed by Chainguard. See How to fix? for Chainguard relevant fixed versions and status.

astral-tokio-tar is a tar archive reading/writing library for async Rust. Versions of astral-tokio-tar prior to 0.5.6 contain a boundary parsing vulnerability that allows attackers to smuggle additional archive entries by exploiting inconsistent PAX/ustar header handling. When processing archives with PAX-extended headers containing size overrides, the parser incorrectly advances stream position based on ustar header size (often zero) instead of the PAX-specified size, causing it to interpret file content as legitimate tar headers. This issue has been patched in version 0.5.6. There are no workarounds.

CVSS Base Scores

version 3.1