CVE-2026-73030

NameCVE-2026-73030
Descriptionunearth through 0.18.2, fixed in commit 6c78164, contains a path traversal vulnerability in the is_within_directory function that fails to normalize paths before validation, allowing ../ sequences to bypass directory containment checks. Attackers can supply malicious tar archives with symlink members or traversal sequences to write files to arbitrary filesystem locations accessible to the process.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
unearth (PTS)bookworm0.7.2+ds-2vulnerable
trixie0.17.5-1vulnerable
forky, sid0.18.2-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
unearthsource(unstable)(unfixed)

Notes

[trixie] - unearth <no-dsa> (Minor issue)
https://github.com/frostming/unearth/issues/180
https://github.com/frostming/unearth/pull/181
Fixed by: https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba

Search for package or bug name: Reporting problems