CVE-2026-73030

NameCVE-2026-73030
Descriptionunearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1144401

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
unearth (PTS)bookworm0.7.2+ds-2vulnerable
trixie0.17.5-1vulnerable
forky, sid0.18.3-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
unearthsource(unstable)0.18.3-11144401

Notes

[trixie] - unearth <no-dsa> (Minor issue)
https://github.com/frostming/unearth/issues/180
https://github.com/frostming/unearth/pull/181
Fixed by: https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba (0.18.3)

Search for package or bug name: Reporting problems