VDB
CVE-2026-73030
CVE-2026-73030
PUBLISHED
CVSS 7.2 HIGH
Reported by VulnCheck · Published August 10, 2026
unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
Risk Scores
CVSS 4.0
7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| frostming | unearth | 0, 6c78164e7bfa28b8b3d6f247b87e560692e3c8ba |
| frostming | unearth | 0, 6c78164e7bfa28b8b3d6f247b87e560692e3c8ba, 0 |
Timeline
- Aug 10, 2026 CVE Published
- Aug 11, 2026 CVE Updated
- Aug 16, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Aug 26, 2026 EPSS Score
- Aug 30, 2026 EPSS Score
- Sep 3, 2026 EPSS Score
- Sep 6, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- Researcher Disclosure technical-descriptionexploit
- Pull Request issue-tracking
- Patch Commit patch
- third-party-advisory