VDB
GO-2026-4636
GO-2026-4636
PUBLISHED
Zarf's symlink targets in archives are not validated against destination directory in github.com/zarf-dev/zarf
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | zarf-dev/zarf | 0.54.0, 0.54.0 |
Timeline
- Mar 10, 2026 CVE Published
- Mar 23, 2026 CVE Updated
- May 1, 2026 Security Advisory