← Back

CVE-2026-29064

nvd nist
Published: Mar 6, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.2
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Exploitability: 1.8 / Impact: 5.8
Source: security-advisories@github.com (Secondary)

Description

Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.

Affected (1)

Products: Lfprojects: Zarf
1 product
Zarf
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 0.54.0 to 0.73.1

References (2)

Source: security-advisories@github.com
ProductRelease Notes
Source: security-advisories@github.com
ExploitVendor Advisory

Timeline

No history available yet.