### [CVE-2025-46394](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46394) ![](https://img.shields.io/static/v1?label=Product&message=BusyBox&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%20&color=brightgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-451%20User%20Interface%20(UI)%20Misrepresentation%20of%20Critical%20Information&color=brightgreen) ### Description In tar in BusyBox through 1.37.0, a TAR archive can have filenames hidden from a listing through the use of terminal escape sequences. ### POC #### Reference No PoCs from references. #### Github - https://github.com/R16008882/CVE-checks-Yocto - https://github.com/kaisensan/desafio-girus-pick