VDB

CVE-2026-73030

CVE-2026-73030 PUBLISHED CVSS 7.2 HIGH

Reported by VulnCheck · Published August 10, 2026

unearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.

Risk Scores

CVSS 4.0
7.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
frostmingunearth0, 6c78164e7bfa28b8b3d6f247b87e560692e3c8ba
frostmingunearth0, 6c78164e7bfa28b8b3d6f247b87e560692e3c8ba, 0

Timeline

  • Aug 10, 2026 CVE Published
  • Aug 11, 2026 CVE Updated
  • Aug 16, 2026 Security Advisory
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
  • Sep 9, 2026 EPSS Score
  • Sep 12, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›