Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1.
Metrics
Affected Vendors & Products
References
History
Mon, 09 Mar 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zarf-dev
Zarf-dev zarf |
|
| Vendors & Products |
Zarf-dev
Zarf-dev zarf |
Fri, 06 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Zarf is an Airgap Native Packager Manager for Kubernetes. From version 0.54.0 to before version 0.73.1, a path traversal vulnerability in archive extraction allows a specifically crafted Zarf package to create symlinks pointing outside the destination directory, enabling arbitrary file read or write on the system processing the package. This issue has been patched in version 0.73.1. | |
| Title | Zarf: Symlink targets in archives are not validated against destination directory | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-03-06T16:13:17.614Z
Updated: 2026-03-06T19:33:38.362Z
Reserved: 2026-03-03T20:51:43.482Z
Link: CVE-2026-29064
Updated: 2026-03-06T19:31:14.526Z
Status : Awaiting Analysis
Published: 2026-03-06T17:16:34.003
Modified: 2026-03-09T13:35:34.633
Link: CVE-2026-29064
No data.