← Back

CVE-2026-65921

nvd nist
Published: Jul 27, 2026Modified: Jul 30, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: reefs@jfrog.com (Secondary)

Description

A path validation weakness in archive extraction/write handling allows entries with traversal sequences to be written outside the intended build artifacts location.

Affected (6)

Products: Jfrog: Artifactory
1 product
Artifactory
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Jfrog
Before 7.111.18
From 7.117.0 to 7.117.25
From 7.125.0 to 7.125.18
From 7.133.0 to 7.133.27
From 7.146.0 to 7.146.34
From 7.161.0 to 7.161.15

References (2)

Timeline

No history available yet.