Project Subscriptions
No data.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hcm4-6hpj-vghm | Zarf's symlink targets in archives are not validated against destination directory |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 06 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1. | |
| Title | Zarf: Symlink targets in archives are not validated against destination directory | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T19:33:38.362Z
Reserved: 2026-03-03T20:51:43.482Z
Link: CVE-2026-29064
Updated: 2026-03-06T19:31:14.526Z
Status : Received
Published: 2026-03-06T17:16:34.003
Modified: 2026-03-06T17:16:34.003
Link: CVE-2026-29064
No data.
OpenCVE Enrichment
No data.
Github GHSA