Gpgtar may follow the symlink to outside, when -C (--directory) option is used. This could be considered a security issue under recommended practice these days.
Reported-by: Oleh Konko https://1seal.org/research/
Major use cases (of no -C), it's gpgtar which creates the directory, so, this case has no problem.
For references, see other CVEs.
- GNU Tar: CVE-2025-45582 https://nvd.nist.gov/vuln/detail/CVE-2025-45582
- node-tar: CVE-2026-23745 https://nvd.nist.gov/vuln/detail/CVE-2026-23745