unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 21:17
Updated : 2026-08-11 18:18
NVD link : CVE-2026-73030
Mitre link : CVE-2026-73030
CVE.ORG link : CVE-2026-73030
JSON object : View
Products Affected
No product.
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
