VDB

GO-2026-4636

GO-2026-4636 PUBLISHED

Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf

Affected Products

VendorProductVersions
github.comzarf-dev/zarf0.54.0, 0.54.0

Timeline

  • Mar 10, 2026 CVE Published
  • Mar 23, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›